CVE-2025-11781

7.8

Circutor · SGE-PLC1000, SGE-PLC50

The Circutor SGE-PLC1000 and SGE-PLC50 firmware version 9.0.2 contains a hardcoded cryptographic key that allows unauthorized actors to bypass security controls and gain full administrative access.

Executive summary

A critical vulnerability involving hardcoded cryptographic keys in legacy Circutor SGE-PLC series devices allows for total administrative compromise through unauthorized firmware manipulation.

Vulnerability

This flaw, categorized as CWE-321, stems from the inclusion of a static authentication key within the device firmware. An attacker with local access can extract this key to forge valid firmware update packages, effectively bypassing all access controls and achieving full administrative privileges.

Business impact

The ability to forge firmware updates presents a severe risk to operational integrity and system security. Because the attacker can gain full administrative control, they could potentially disrupt industrial processes, manipulate data, or maintain persistent access to the network, leading to significant operational downtime and safety concerns. With a CVSS score of 7.8, this vulnerability represents a high-severity risk that demands immediate attention for any remaining deployments.

Remediation

Immediate Action: As the affected units were discontinued in 2015 and subsequent replacements are also obsolete, administrators must prioritize the decommissioning of these devices and transition to the current GEDE EDC product line.

Proactive Monitoring: Monitor network traffic for unauthorized firmware update attempts or anomalous administrative activity originating from legacy concentrator hardware.

Compensating Controls: Since software patches are unavailable for these discontinued units, isolate the affected devices within a restricted management VLAN and implement strict physical access controls to prevent the local extraction of keys.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the end-of-life status of the SGE-PLC1000 and SGE-PLC50 units, formal patching is not an option. Security teams must treat these devices as inherently compromised if they cannot be physically secured or network-isolated. The most effective strategy to mitigate this high-severity risk is to expedite the replacement of these legacy concentrators with supported, modern hardware.

More Circutor CVEs

Sources

Originally found and disclosed by Gabriel Gonzalez and Sergio Ruiz, per the CVE Program record.