← Back to browse · API

CVE-2017-2898

Severity
CRITICAL
CVSS
9.9
EPSS
0.01556
Risk score
40.14
CISA KEV
No
PoC
No
Published
2017-11-07
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2017-12039, GHSA-MHXP-XVR8-VWJM
Products
Circle Media:Circle firmware 2.0.1
Sources
euvd EUVD-2017-12039

Description

An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be installed in the device resulting in arbitrary code execution. An attacker can send a series of packets to trigger this vulnerability.

References