Fiche vulnérabilité
CVE-2025-11781 : faille élevée circutor sge-plc1000 firmware (CVSS 7.8)
Description
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 2 déc. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- circutor sge-plc1000 firmware
- circutor sge-plc50 firmware