7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the parameter is too large, it will access memory beyond the limits.
Basic Information
ID
CVE-2025-11789
Source
INCIBE
Published
Dec 2, 2025 at 13:04
Modified
Dec 2, 2025 at 13:27
Affected Product
Vendor
SGE-PLC1000 SGE-PLC50
Product
Circutor
Version
9.0.2
Affected Versions
SGE-PLC1000 SGE-PLC50 Circutor 9.0.2