Circutor Sge-Plc1000 vulnerabilities
2 known vulnerabilities affecting circutor/sge-plc1000.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2021-33841P2CRITICALCVSS 9.8v0.9.2b2021-06-09
CVE-2021-33841 [CRITICAL] CWE-78 CVE-2021-33841: SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowin
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
nvd
CVE-2021-33842P3HIGHCVSS 8.8v0.9.2b2021-06-09
CVE-2021-33842 [HIGH] CWE-565 CVE-2021-33842: Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware versi
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
nvd