An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the rclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
Link | Tags |
---|---|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0418 | third party advisory exploit |