Vulnerabilities > Circutor > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-18 CVE-2024-8892 Unspecified vulnerability in Circutor Tcp2Rs+ Firmware 1.3B
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use.
network
low complexity
circutor
critical
9.1
2024-09-18 CVE-2024-8889 Unspecified vulnerability in Circutor Tcp2Rs+ Firmware 1.3B
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use.
network
low complexity
circutor
critical
9.1
2021-12-02 CVE-2021-26777 Classic Buffer Overflow vulnerability in Circutor Compact Dc-S Basic Firmware 1.2.17
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.
network
low complexity
circutor CWE-120
critical
9.8
2021-06-09 CVE-2021-33841 OS Command Injection vulnerability in Circutor Sge-Plc1000 Firmware 0.9.2B
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
network
low complexity
circutor CWE-78
critical
9.8