Meetcircle's vulnerability footprint centers on a parental-control and device-management platform, Circle with Disney, that operates across consumer home networks with modest but recurring exposure. The product's vulnerability surface concentrates on authentication and command-execution boundaries—specifically OS command injection, authentication bypass through spoofing, improper authentication mechanisms, and certificate validation gaps—reflecting the firmware-level and network-management access model inherent to home-router and device-control appliances. While the volume of disclosures remains modest relative to the broader landscape, they reach a meaningful share of serious severity, underscoring the privilege and network position such devices occupy within home environments. Defenders managing or monitoring this product should prioritize patches addressing authentication and OS-command handling, as these weakness classes directly affect the integrity of parental controls and the isolation of managed devices. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meetcircle over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12085CRITICAL An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Cir | Nov 7, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-2864CRITICAL An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authenticatio | Nov 7, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-2881HIGH An exploitable vulnerability exists in the torlist update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the product to run | Nov 7, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-2866HIGH An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS command injection. An attacker | Nov 7, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-2915HIGH An exploitable vulnerability exists in the WiFi configuration functionality of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute a | Nov 7, 2017 | 8.0 | 26 | NO | NO |
CVE-2017-2914HIGH An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication ro | Nov 7, 2017 | 8.1 | 26 | NO | NO |
CVE-2017-2883HIGH An exploitable vulnerability exists in the database update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to exe | Nov 7, 2017 | 8.1 | 26 | NO | NO |
CVE-2017-2882HIGH An exploitable vulnerability exists in the servers update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to over | Nov 7, 2017 | 8.1 | 26 | NO | NO |
CVE-2017-2916HIGH An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary | Nov 7, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-2917HIGH An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injec | Nov 7, 2017 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meetcircle.
Media articles that mention a CVE ID that affects a product developed by Meetcircle — matched by CVE ID, not by vendor name.