CVE-2025-11788 is a critical heap-based buffer overflow vulnerability affecting Circutor SGE-PLC1000 and SGE-PLC50 devices running firmware v9.0.2. This flaw allows an unauthenticated attacker to provide unlimited input to the 'meter' parameter, which is then copied to a fixed-size buffer without validation, leading to a buffer overflow. With a CVSS score of 9.8 (Critical), this vulnerability presents a severe risk, enabling remote code execution, denial of service, and full compromise of affected systems. The attack requires no user interaction or privileges, making it easily exploitable over the network. While there is no evidence of active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.2CPE matchmatch criteria | cpe:2.3:o:circutor:sge-plc1000_firmware:9.0.2:*:*:*:*:*:*:* | ||
9.0.2CPE matchmatch criteria | cpe:2.3:o:circutor:sge-plc50_firmware:9.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.