CVE-2025-11781
HIGHCircutor SGE-PLC1000/SGE-PLC50 v9.0.2 - Privilege Escalation
Title source: llmDescription
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
4.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-321
Status
published
Products (2)
circutor/sge-plc1000_firmware
9.0.2
circutor/sge-plc50_firmware
9.0.2
Published
Dec 02, 2025
Tracked Since
Feb 18, 2026