PT-2025-48671 · Circutor · Circutor Sge-Plc50+1

Published

2025-12-02

·

Updated

2026-02-02

·

CVE-2025-11781

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Circutor SGE-PLC1000/SGE-PLC50 version 9.0.2
Description The affected firmware contains a hardcoded static authentication key. An attacker with local access can extract this key by analyzing the firmware image or memory dump. This allows the creation of valid firmware update packages, bypassing access controls and granting full administrative privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-11781

Affected Products

Circutor Sge-Plc1000
Circutor Sge-Plc50