Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Circutor

First CVE: Jun 9, 2021Active for: 5 yearsTotal CVEs: 22
43.8
VTI Score
High

Circutor manufactures programmable logic controllers and related industrial automation equipment, with its vulnerability disclosures centered on a narrow product line including the SGE-PLC1000 and SGE-PLC50 series. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, reflecting the memory-safety exposures endemic to firmware and embedded control systems. Recurring weakness classes include stack-based and heap-based buffer overflows, classic buffer-copy issues, and OS command injection, all of which represent high-risk primitives in devices that often run unpatched in operational environments and lack compensating network segmentation. Defenders should prioritize inventory and isolation of affected PLCs and treat firmware updates for this vendor as critical; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Circutor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2021
5 years ago
Most Recent CVE
Dec 2, 2025
234 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-11788CRITICAL
Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to
Dec 2, 20259.833NONO
CVE-2025-11779CRITICAL
Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration func
Dec 2, 20259.831NONO
CVE-2025-11785CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fix
Dec 2, 20259.830NONO
CVE-2025-11783CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled usernam
Dec 2, 20259.830NONO
CVE-2025-11778CRITICAL
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' functi
Dec 2, 20259.830NONO
CVE-2021-26777CRITICAL
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to
Dec 2, 20219.830NONO
CVE-2025-11786CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell
Dec 2, 20259.829NONO
CVE-2025-11784CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixe
Dec 2, 20259.829NONO
CVE-2025-11782CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-control
Dec 2, 20259.829NONO
CVE-2025-11780CRITICAL
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-
Dec 2, 20259.829NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
36%
59%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network19 (86.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (9.1%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (13.6%)
High0 (0.0%)
None19 (86.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Circutor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Circutor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Circutor's Products

View all 3 CNAs →

Top CWEs