CVE-2025-11781
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321
Uso de claves de cifrado embebidas en el software
Fecha de publicación:
02/12/2025
Última modificación:
02/12/2025
Descripción
*** Pendiente de traducción *** Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware update packages. This bypasses all intended access controls and grants full administrative privileges.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA



