Перейти к содержимому
Noroxi

Записи orange

8 опубликованных записей вендора orange.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 18

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

8 записей
  • CVE-2018-20377
    41В плане

    Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to

    КритическаяCVSS 9,8Proof of conceptEPSS 8 %

    orange · arv7519rw22 livebox 2.1 firmware23 дек. 2018 г.

  • CVE-2018-18375
    39Наблюдать

    goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    orange · airbox firmware15 окт. 2018 г.

  • CVE-2014-3150
    36Наблюдать

    Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    orange · livebox 1.1 firmware15 нояб. 2017 г.

  • CVE-2018-20577
    36Наблюдать

    Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.

  • CVE-2018-18376
    30Наблюдать

    goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    orange · airbox firmware15 окт. 2018 г.

  • CVE-2018-20575
    30Наблюдать

    Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.

  • CVE-2018-18377
    30Наблюдать

    goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    orange · airbox firmware15 окт. 2018 г.

  • CVE-2018-20576
    21Наблюдать

    Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone cal

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.