Circontrol

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 10
    Known Exploited: 0
    4
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-8006

    The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.

    Last Modified: Nov 04, 2025
    Published: Apr 12, 2024

    CVE-2018-17922

    Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.

    Last Modified: Nov 21, 2024
    Published: Nov 02, 2018

    CVE-2018-17918

    Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.

    Last Modified: Nov 21, 2024
    Published: Nov 02, 2018

    CVE-2018-16672

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.

    Last Modified: Nov 21, 2024
    Published: Sep 26, 2018

    CVE-2018-16671

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.

    Last Modified: Nov 21, 2024
    Published: Sep 18, 2018
    Items Per Page