Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4px-6397-h93g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH server.

A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH server.

EPSS

Процентиль: 60%
0.00392
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8
nvd
больше 8 лет назад

A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API call to enable the SSH server.

EPSS

Процентиль: 60%
0.00392
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-862