An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-09-16T16:28:53.784Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2890

No data.

Status : Deferred
Published: 2017-11-07T16:29:00.670
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-2890

No data.