S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-16670 Scanner

Detects 'Information Disclosure' vulnerability in CIRCONTROL CirCarLife affects v. before 4.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16670
5.3
CVSS

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CIRCONTROL CirCarLife is a software product that is widely used for electric vehicle (EV) management. It is specifically designed to provide EV drivers with the ability to monitor and manage the charging of their vehicles so that they can make informed decisions regarding charging schedules, energy consumption, and more. The software is available for use on a variety of devices, from desktop computers to smartphones, making it accessible and convenient for users.

However, a recent discovery has revealed a vulnerability in CIRCONTROL CirCarLife known as CVE-2018-16670. This vulnerability is caused by a lack of authentication for /html/devstat.html, which can lead to the disclosure of sensitive information. This information includes the status of a Programmable Logic Controller (PLC) device, and without proper authentication, anyone can gain access to it.

When this vulnerability is exploited, it can lead to serious consequences. An attacker can gain unauthorized access to the management system and manipulate the charging process of EVs. They could also alter the logging and diagnostic processes, which can compromise the overall safety of the EV charging system. Moreover, an attack can lead to the theft of personal information and financial data, leaving the user vulnerable to identity theft and fraud.

At s4e.io, we provide pro features that make it easy and convenient for users to detect vulnerabilities in their digital assets. Our platform offers a comprehensive suite of tools and services that enable users to secure their devices and networks against potential threats. With features like vulnerability scanning, patch management, and threat detection, we help users stay informed and proactive when it comes to protecting their digital assets. So, whether you're a business owner or an individual user, make sure to take advantage of all that our platform has to offer and safeguard your assets today!

 

REFERENCES

Solution Advice

Thankfully, there are precautions that can be taken to prevent this vulnerability from being exploited. These include:

  • Regularly updating the software to ensure that it is up-to-date with the latest security patches.
  • Keeping all internet-connected devices up-to-date with the latest firmware and software.
  • Restricting access to the management system to only authorized users with strong passwords.
  • Implementing firewalls and intrusion detection systems to monitor and block unauthorized access attempts.
  • Monitoring the system logs to detect any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16670 scanner - Information Disclosure vulnerability in CIRCONTROL CirCarLife | S4E