Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Circontrol

First CVE: Jun 22, 2018Active for: 8 yearsTotal CVEs: 10
52.3
VTI Score
TOP TARGET

Circontrol develops electric vehicle charging infrastructure and SCADA control systems, notably including its Circarlife charging platform and Raption server, that manage distributed networked devices in energy and transportation environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value and often internet-exposed nature of charging-network infrastructure; the exposure concentrates in authentication and credential-handling weaknesses—including improper authentication, insufficiently protected credentials, authentication bypass, and sensitive information disclosure—that recur across its product line and firmware. Defenders should treat authentication controls in this vendor's deployed systems as high-priority hardening targets, particularly for internet-reachable instances; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Circontrol over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2018
8 years ago
Most Recent CVE
Apr 12, 2024
832 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12634CRITICAL
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
Jun 22, 20189.879NOYES
CVE-2018-16670MEDIUM
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
Sep 18, 20185.340NOYES
CVE-2018-16668MEDIUM
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
Sep 18, 20185.332NOYES
CVE-2018-17922CRITICAL
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
Nov 2, 20189.831NONO
CVE-2018-17918CRITICAL
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
Nov 2, 20189.831NONO
CVE-2018-16671MEDIUM
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
Sep 18, 20185.331NOYES
CVE-2018-16669CRITICAL
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML f
Sep 18, 20189.829NONO
CVE-2020-8006HIGH
The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1
Apr 12, 20248.826NONO
CVE-2018-12635HIGH
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
Jun 22, 20187.523NONO
CVE-2018-16672MEDIUM
An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authe
Sep 26, 20186.522NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
20%
40%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
40.0% of CVEs· 98th percentile
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Circontrol.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Circontrol — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Circontrol's Products

View all 2 CNAs →

Top CWEs