CVE-2017-12096 describes an exploitable vulnerability in the WiFi management of Circle with Disney devices. An attacker can create a malicious Access Point with the same name as a legitimate one, tricking the Circle device into connecting to an untrusted network. This attack requires physical proximity (adjacent network access) and involves sending deauthentication packets to trigger the vulnerability, leading to a high impact on availability. While the CVSS score is 6.5 (MEDIUM), there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1CPE matchmatch criteria | cpe:2.3:o:meetcircle:circle_with_disney_firmware:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.