orange records
8 published records for vendor orange.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-254 7PK - Security Features1
- CWE-330 Use of Insufficiently Random Values1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-20377Proof of concept | Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to orange · arv7519rw22 livebox 2.1 firmware | Critical9.8 | — | 7.7% | Dec 23, 2018 |
39Monitor | CVE-2018-18375No exploit | goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the orange · airbox firmware · CWE-330 | Critical9.8 | — | 1.3% | Oct 15, 2018 |
36Monitor | CVE-2014-3150No exploit | Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive orange · livebox 1.1 firmware · CWE-254 | High8.8 | — | 1.9% | Nov 15, 2017 |
36Monitor | CVE-2018-20577No exploit | Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exeorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Critical9.1 | — | 0.6% | Dec 28, 2018 |
30Monitor | CVE-2018-18376No exploit | goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devicesorange · airbox firmware · CWE-200 | High7.5 | — | 1.5% | Oct 15, 2018 |
30Monitor | CVE-2018-20575No exploit | Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.orange · arv7519rw22 livebox 2.1 firmware · CWE-20 | High7.5 | — | 1.0% | Dec 28, 2018 |
30Monitor | CVE-2018-18377No exploit | goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to loginorange · airbox firmware · CWE-862 | High7.5 | — | 0.9% | Oct 15, 2018 |
21Monitor | CVE-2018-20576No exploit | Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Medium5.4 | — | 0.4% | Dec 28, 2018 |
- CVE-2018-2037741Plan
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to
CriticalCVSS 9.8Proof of conceptEPSS 8%orange · arv7519rw22 livebox 2.1 firmwareDec 23, 2018
- CVE-2018-1837539Monitor
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the
CriticalCVSS 9.8No exploitEPSS 1%orange · airbox firmwareOct 15, 2018
- CVE-2014-315036Monitor
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive
HighCVSS 8.8No exploitEPSS 2%orange · livebox 1.1 firmwareNov 15, 2017
- CVE-2018-2057736Monitor
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe
CriticalCVSS 9.1No exploitEPSS 1%orange · arv7519rw22 livebox 2.1 firmwareDec 28, 2018
- CVE-2018-1837630Monitor
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices
HighCVSS 7.5No exploitEPSS 2%orange · airbox firmwareOct 15, 2018
- CVE-2018-2057530Monitor
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.
HighCVSS 7.5No exploitEPSS 1%orange · arv7519rw22 livebox 2.1 firmwareDec 28, 2018
- CVE-2018-1837730Monitor
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login
HighCVSS 7.5No exploitEPSS 1%orange · airbox firmwareOct 15, 2018
- CVE-2018-2057621Monitor
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone cal
MediumCVSS 5.4No exploitEPSS 0%orange · arv7519rw22 livebox 2.1 firmwareDec 28, 2018