CVE-2025-11787: Circutor Sge-PLC1000 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

Affected products

  • Circutor Sge-PLC1000 Firmware: version 9.0.2 only
  • Circutor Sge-PLC50 Firmware: version 9.0.2 only

Published 2025-12-02. Last modified 2026-09-26.