Circutor SGE-PLC1000
cpe:2.3:h:circutor:sge-plc1000:*:*:*:*:*:*:*, +1 more
- 9.0.2
A command injection vulnerability has been identified in Circutor SGE-PLC1000 and SGE-PLC50 devices running version 9.0.2. This vulnerability arises in the operating system and can be exploited through the 'GetDNS()', 'CheckPing()', and 'TraceRoute()' functions.
Exploitation of this vulnerability allows for command injection on the operating system level, where an attacker can execute arbitrary commands with the same privileges as the application.
Circutor SGE-PLC1000 and SGE-PLC50 units were discontinued in 2015. Users are advised to update to the latest available version (2.0.4) or, at a minimum, to 2.0.0. For units that have been replaced by the GEDE EDC, it is recommended to update to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.