CVE-2025-11787

8.8

Circutor · SGE-PLC1000 and SGE-PLC50

A command injection vulnerability in Circutor SGE-PLC1000 and SGE-PLC50 version 9.0.2 allows for OS command execution via the GetDNS, CheckPing, and TraceRoute functions.

Executive summary

An OS command injection vulnerability in legacy Circutor SGE-PLC1000 and SGE-PLC50 units poses a high risk of total system compromise for authenticated users.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered through improper neutralization of special elements in the GetDNS, CheckPing, and TraceRoute functions. The CVSS vector indicates that a low-privileged authenticated user can trigger this vulnerability, although it requires user interaction.

Business impact

Successful exploitation of this vulnerability results in full system compromise, allowing an attacker to execute arbitrary commands at the operating system level. Given the CVSS score of 8.8, this represents a significant threat to industrial control environments, potentially leading to unauthorized system manipulation, service disruption, and loss of operational integrity.

Remediation

Immediate Action: Because the affected hardware is discontinued, users should migrate to the current GEDE EDC product line. If migration is not immediately possible, isolate these units within a protected network segment to restrict access to the vulnerable functions.

Proactive Monitoring: Monitor network traffic and device logs for unusual execution patterns related to diagnostic functions like ping or traceroute. Implement strict access controls to limit the number of users who can interact with the device management interface.

Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to inspect and block malicious input strings targeting the diagnostic functions. Ensure that management interfaces are not exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with the end-of-life status of the affected hardware, necessitates an immediate transition to modern, supported equipment. Organizations currently utilizing SGE-PLC1000 or SGE-PLC50 units must prioritize the replacement of these devices to eliminate the risk of remote command injection and potential operational impact.

More Circutor CVEs

Sources

Originally found and disclosed by Gabriel Gonzalez and Sergio Ruiz, per the CVE Program record.