← Back to browse · API

CVE-2017-2916

Severity
CRITICAL
CVSS
9.9
EPSS
0.02251
Risk score
40.39
CISA KEV
No
PoC
No
Published
2017-11-07
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2017-12057, GHSA-4PGP-X4G6-96CG
Products
Circle Media:Circle firmware 2.0.1
Sources
euvd EUVD-2017-12057

Description

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can send an HTTP request to trigger this vulnerability.

References