CVE-2017-12085: Meetcircle Circle With Disney Firmware

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network connectivity to the Internet to trigger this vulnerability.

Affected products

  • Meetcircle Circle With Disney Firmware: version 2.0.1 only

Published 2017-11-07. Last modified 2026-06-17.