CVE-2017-2912: Meetcircle Circle With Disney Firmware
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
Affected products
- Meetcircle Circle With Disney Firmware: version 2.0.1 only
Published 2017-11-07. Last modified 2026-06-17.