VYPR

Circle With Disney Firmware

by Meetcircle

CVEs (22)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-2911Med0.385.90.00Nov 7, 2017An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the rclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
CVE-2017-12083Med0.385.80.00Nov 7, 2017An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware 2.0.1. A specially crafted set of packets can make the Disney Circle dump strings from an internal database into an HTTP response. An attacker needs network connectivity to the Internet to trigger this vulnerability.

Page 2 of 2