Arbitrary File Overwrite Vulnerability in Circle with Disney Firmware 2.0.1

Arbitrary File Overwrite Vulnerability in Circle with Disney Firmware 2.0.1

CVE-2017-2916 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can send an HTTP request to trigger this vulnerability.

Learn more about our Api Penetration Testing.