Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/circutor/SGE-PLC1000

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the parameter is too large, it will access memory beyond the limits.

Join the discussion

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the 'meter' parameter.

Join the discussion

CVE-2025-11782 is a high-severity stack-based buffer overflow vulnerability in Circutor SGE-PLC1000 and SGE-PLC50 devices, specifically version 9.0.2. The flaw exists in the 'ShowDownload()' function, which uses an unsafe sprintf() call to copy user-controlled input from the 'meter' parameter into a fixed 64-byte buffer without length validation. An attacker with low privileges but network access can exploit this vulnerability by sending a crafted 'meter' parameter value exceeding the buffer size, potentially leading to arbitrary code execution or denial of service. No user interaction is required, and the vulnerability affects confidentiality, integrity, and availability. Although no known exploits are currently in the wild, the high CVSS score (8.5) indicates significant risk. European organizations using these Circutor PLC devices, especially in critical infrastructure or industrial environments, should prioritize patching or mitigating this issue. Countries with substantial industrial automation sectors and Circutor product deployments, such as Germany, France, Spain, and Italy, are most likely to be impacted.

Join the discussion

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.

Join the discussion

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the “meter” parameter.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/circutor/SGE-PLC1000
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses