Circontrol develops electric vehicle charging infrastructure and SCADA control systems, notably including its Circarlife charging platform and Raption server, that manage distributed networked devices in energy and transportation environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value and often internet-exposed nature of charging-network infrastructure; the exposure concentrates in authentication and credential-handling weaknesses—including improper authentication, insufficiently protected credentials, authentication bypass, and sensitive information disclosure—that recur across its product line and firmware. Defenders should treat authentication controls in this vendor's deployed systems as high-priority hardening targets, particularly for internet-reachable instances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Circontrol over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12634CRITICAL CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. | Jun 22, 2018 | 9.8 | 79 | NO | YES |
CVE-2018-16670MEDIUM An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html. | Sep 18, 2018 | 5.3 | 40 | NO | YES |
CVE-2018-16668MEDIUM An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository. | Sep 18, 2018 | 5.3 | 32 | NO | YES |
CVE-2018-17922CRITICAL Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication. | Nov 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17918CRITICAL Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page. | Nov 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-16671MEDIUM An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id. | Sep 18, 2018 | 5.3 | 31 | NO | YES |
CVE-2018-16669CRITICAL An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML f | Sep 18, 2018 | 9.8 | 29 | NO | NO |
CVE-2020-8006HIGH The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1 | Apr 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2018-12635HIGH CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs. | Jun 22, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-16672MEDIUM An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authe | Sep 26, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Circontrol.
Media articles that mention a CVE ID that affects a product developed by Circontrol — matched by CVE ID, not by vendor name.