High severity8.1NVD Advisory· Published Nov 7, 2017· Updated May 13, 2026
CVE-2017-2914
CVE-2017-2914
Description
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the device to grant unintended administrative access. An attacker needs network connectivity to the device to trigger this vulnerability.
Affected products
2- cpe:2.3:o:meetcircle:circle_with_disney_firmware:2.0.1:*:*:*:*:*:*:*
- Circle Media/Circlev5Range: firmware 2.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0421nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.