CVE detail
CVE-2025-11789 — CVE-2025-11789
Published 2025-12-02 · Modified 2026-06-17 · Vendor circutor · Product sge-plc1000_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0026
EPSS probability
exploitation probability, 30d
17.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parameter to an integer using 'atoi()' and then uses it as an index in the 'FilesDownload' array with '(&FilesDownload)[iVar2]'. If the parameter is too large, it will access memory beyond the limits.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References