CVE-2017-2916
HIGHCircle with Disney 2.0.1 - Arbitrary File Write via /api/CONFIG/restore
Title source: llmDescription
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can send an HTTP request to trigger this vulnerability.
References (1)
Core 1
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0423
Scores
CVSS v3
8.8
EPSS
0.0225
EPSS Percentile
80.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-59
Status
published
Products (2)
Circle Media/Circle
firmware 2.0.1
meetcircle/circle_with_disney_firmware
2.0.1
Published
Nov 07, 2017
Tracked Since
Feb 18, 2026