ZeroHour

CVE-2017-12096

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p50
Published
()
Modified
Description

An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker needs to setup an Access Point reachable by the device and to send a series of spoofed "deauth" packets to trigger this vulnerability.

Vendors
meetcircle
Products
circle with disney firmware
Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.