LiveActive security incident?Get immediate response
CVE Record

CVE-2017-12096: An exploitable vulnerability exists in the WiFi management of Circle with Disney.

An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker needs to setup an Access Point reachable by the device and to send a series of spoofed "deauth" packets to trigger this vulnerability.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Circle with Disney firmware 2.0.1 can be forced onto an untrusted WiFi network by a nearby attacker impersonating the expected network. The main business risk is device outage or loss of reliable control, not data theft based on the provided CVSS impact.

Executive priority

Treat as a moderate operational risk for environments still using affected Circle devices. Prioritize inventory and remediation planning over emergency response unless outages or suspicious WiFi activity are observed.

Technical view

The issue is in WiFi management. CVSS 3.0 is 6.5, adjacent attack vector, low complexity, no privileges, no user interaction, unchanged scope, and high availability impact. Sources identify Circle Media Circle firmware 2.0.1 as affected.

Likely exposure

Exposure appears limited to Circle with Disney devices running firmware 2.0.1 and reachable by a nearby attacker over WiFi range. The bundle does not identify other products or versions.

Exploitation context

The CVE describes a crafted access point with the same network name and spoofed deauthentication traffic. CISA KEV is false in the bundle, and no cited source here supports active exploitation.

Researcher notes

The source bundle names no CWE and provides no patch status. Avoid expanding scope beyond Circle firmware 2.0.1. The core impact is availability, with CVSS confidentiality and integrity impacts listed as none.

Mitigation direction

  • Check Circle Media and Talos guidance for fixed firmware or supported remediation.
  • Upgrade affected firmware if a vendor-supported update is available.
  • Retire or replace unsupported affected devices if no update exists.
  • Restrict use near untrusted WiFi environments where practical.
  • Monitor for unexpected WiFi association changes or repeated device outages.

Validation and detection

  • Inventory Circle with Disney devices and record firmware versions.
  • Flag any Circle device running firmware 2.0.1 as potentially affected.
  • Review wireless monitoring for duplicate SSIDs near affected devices.
  • Check logs or alerts for unexplained WiFi disconnect patterns.
  • Document whether vendor remediation guidance is available.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-12096 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.0MediumCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

6.5Medium
CVSS 3.0 vector shape for CVE-2017-12096Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Circle MediaCirclefirmware 2.0.1Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.