Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrhq-7vp6-hj9f

Опубликовано: 02 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.8

Описание

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.

EPSS

Процентиль: 5%
0.00021
Низкий

8.6 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-321