Meetcircle
Meetcircle Circle With Disney Firmware: vulnerabilidades y CVE
Meetcircle Circle With Disney Firmware tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-12095 | Media (6.5) | 0.63% | — | 5 abr 2018 | An exploitable vulnerability exists in the WiFi Access Point feature of Circle with Disney running firmware 2.0.1. A series of WiFi packets can force Circle to setup an Access Point with default credentials. An attacker… |
| CVE-2017-2917 | Alta (8.8) | 3.2% | — | 7 nov 2017 | An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP… |
| CVE-2017-2916 | Alta (8.8) | 2.3% | — | 7 nov 2017 | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can… |
| CVE-2017-2915 | Alta (8) | 1.4% | — | 7 nov 2017 | An exploitable vulnerability exists in the WiFi configuration functionality of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary shell commands. An attacker… |
| CVE-2017-2914 | Alta (8.1) | 1.6% | — | 7 nov 2017 | An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the… |
| CVE-2017-2913 | Media (5.9) | 0.67% | — | 7 nov 2017 | An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate than intended. An… |
| CVE-2017-2912 | Media (5.9) | 0.66% | — | 7 nov 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different… |
| CVE-2017-2911 | Media (5.9) | 0.67% | — | 7 nov 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the rclient daemon to accept a different… |
| CVE-2017-2898 | Alta (7.5) | 1.6% | — | 7 nov 2017 | An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be installed in the… |
| CVE-2017-2890 | Alta (8.8) | 2.6% | — | 7 nov 2017 | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an… |
| CVE-2017-2889 | Alta (7.5) | 1.5% | — | 7 nov 2017 | An exploitable Denial of Service vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A large amount of simultaneous TCP connections causes the APID daemon to repeatedly fork, causing the… |
| CVE-2017-2884 | Alta (7.5) | 1.4% | — | 7 nov 2017 | An exploitable vulnerability exists in the user photo update functionality of Circle with Disney running firmware 2.0.1. A repeated set of specially crafted API calls can cause the device to corrupt essential memory,… |
| CVE-2017-2883 | Alta (8.1) | 2.4% | — | 7 nov 2017 | An exploitable vulnerability exists in the database update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to execute arbitrary code. An attacker needs… |
| CVE-2017-2882 | Alta (8.1) | 2.0% | — | 7 nov 2017 | An exploitable vulnerability exists in the servers update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to overwrite sensitive files, resulting in… |
| CVE-2017-2881 | Alta (8.8) | 0.80% | — | 7 nov 2017 | An exploitable vulnerability exists in the torlist update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An… |
| CVE-2017-2866 | Alta (8.8) | 3.1% | — | 7 nov 2017 | An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger… |
| CVE-2017-2865 | Alta (7.5) | 0.56% | — | 7 nov 2017 | An exploitable vulnerability exists in the firmware update functionality of Circle with Disney. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept… |
| CVE-2017-2864 | Crítica (9.8) | 1.5% | — | 7 nov 2017 | An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker… |
| CVE-2017-12096 | Media (6.5) | 0.68% | — | 7 nov 2017 | An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker… |
| CVE-2017-12094 | Media (6.5) | 0.87% | — | 7 nov 2017 | An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup… |
| CVE-2017-12085 | Crítica (9.8) | 1.7% | — | 7 nov 2017 | An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network… |
| CVE-2017-12084 | Media (6.6) | 0.97% | — | 7 nov 2017 | A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent… |
| CVE-2017-12083 | Media (5.3) | 1.1% | — | 7 nov 2017 | An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware 2.0.1. A specially crafted set of packets can make the Disney Circle dump strings from an internal… |