An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-09-16T16:28:53.784Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2890

No data.

Status : Modified
Published: 2017-11-07T16:29:00.670
Modified: 2024-11-21T03:24:24.127
Link: CVE-2017-2890

No data.