← Back to browse · API

CVE-2017-2890

Severity
CRITICAL
CVSS
9.9
EPSS
0.02631
Risk score
40.52
CISA KEV
No
PoC
No
Published
2017-11-07
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2017-12031, GHSA-36R9-R78P-JQG9
Products
Circle Media:Circle firmware 2.0.1
Sources
euvd EUVD-2017-12031

Description

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability.

References