CVE-2025-11781 Details
Description
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.
A vulnerability exists in Circutor SGE-PLC1000 and SGE-PLC50 devices running firmware version 9.0.2, due to the presence of hardcoded cryptographic keys. This static authentication key can be extracted by an attacker with local access to the device, such as through firmware analysis or memory dumping. Once obtained, the key can be used to create legitimate firmware update packages, bypassing all access controls and granting full administrative rights on the device.
Circutor SGE-PLC1000 and SGE-PLC50 units were discontinued in 2015. Users are advised to update to the latest available version (2.0.4) or, at a minimum, to 2.0.0. For units that have been replaced by the GEDE EDC, it is recommended to update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products-0 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| circutor sge-plc1000 firmware | 9.0.2 |
CPE
Remediation
| |
| circutor sge-plc1000 | All versions |
CPE
Remediation
| |
| circutor sge-plc50 firmware | 9.0.2 |
CPE
Remediation
| |
| circutor sge-plc50 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 3, 2025 | Initial Analysis | [email protected] |
| Dec 2, 2025 | New CVE Received | [email protected] |