Junglewise Threat Intelligence

CVE-2025-11782: Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format

CVE-2025-11782 · Severity: critical · CVSS 9.8 · Published 2025-12-02

Technologies: Circutor Sge-Plc50, Circutor Sge-Plc50 Firmware, Circutor Sge-Plc1000 Firmware, Circutor Sge-Plc1000. Vendors: Circutor.

Executive brief

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without checking the length. An attacker can provide an excessively long value for the 'meter' parameter that exceeds the 64-byte buffer size.

Affected products

  • circutor sge-plc50
  • circutor sge-plc50_firmware
  • circutor sge-plc1000_firmware
  • circutor sge-plc1000

Related threats