CVE-2017-8867 describes a vulnerability in Elemental Path's CogniToys Dino smart toys (firmware up to 0.0.794) where AES-128 in ECB mode is used for voice traffic encryption. This weak encryption allows an attacker to map encrypted traffic to specific AES key indices, potentially enabling eavesdropping on sensitive child voice communications. The vulnerability has a CVSS score of 5.9 (MEDIUM), indicating a network-based attack with high confidentiality impact but high attack complexity. There is no known exploit code available, it is not on the KEV catalog, and it has received minimal community discussion or media coverage, suggesting low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.0.794CPE matchmatch criteria | cpe:2.3:o:cognitoys:stemosaur_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.