Circutor manufactures programmable logic controllers and related industrial automation equipment, with its vulnerability disclosures centered on a narrow product line including the SGE-PLC1000 and SGE-PLC50 series. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, reflecting the memory-safety exposures endemic to firmware and embedded control systems. Recurring weakness classes include stack-based and heap-based buffer overflows, classic buffer-copy issues, and OS command injection, all of which represent high-risk primitives in devices that often run unpatched in operational environments and lack compensating network segmentation. Defenders should prioritize inventory and isolation of affected PLCs and treat firmware updates for this vendor as critical; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Circutor over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11788CRITICAL Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to | Dec 2, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11779CRITICAL Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration func | Dec 2, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-11785CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fix | Dec 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-11783CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled usernam | Dec 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-11778CRITICAL Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' functi | Dec 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2021-26777CRITICAL Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to | Dec 2, 2021 | 9.8 | 30 | NO | NO |
CVE-2025-11786CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-11784CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixe | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-11782CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-control | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-11780CRITICAL Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed- | Dec 2, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Circutor.
Media articles that mention a CVE ID that affects a product developed by Circutor — matched by CVE ID, not by vendor name.