orange kayıtları
orange üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-254 7PK - Security Features1
- CWE-330 Use of Insufficiently Random Values1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2018-20377Kavram kanıtı | Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to orange · arv7519rw22 livebox 2.1 firmware | Kritik9,8 | — | %7,7 | 23 Ara 2018 |
39İzleyin | CVE-2018-18375İstismar yok | goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the orange · airbox firmware · CWE-330 | Kritik9,8 | — | %1,3 | 15 Eki 2018 |
36İzleyin | CVE-2014-3150İstismar yok | Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive orange · livebox 1.1 firmware · CWE-254 | Yüksek8,8 | — | %1,9 | 15 Kas 2017 |
36İzleyin | CVE-2018-20577İstismar yok | Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exeorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Kritik9,1 | — | %0,6 | 28 Ara 2018 |
30İzleyin | CVE-2018-18376İstismar yok | goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devicesorange · airbox firmware · CWE-200 | Yüksek7,5 | — | %1,5 | 15 Eki 2018 |
30İzleyin | CVE-2018-20575İstismar yok | Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.orange · arv7519rw22 livebox 2.1 firmware · CWE-20 | Yüksek7,5 | — | %1,0 | 28 Ara 2018 |
30İzleyin | CVE-2018-18377İstismar yok | goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to loginorange · airbox firmware · CWE-862 | Yüksek7,5 | — | %0,9 | 15 Eki 2018 |
21İzleyin | CVE-2018-20576İstismar yok | Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Orta5,4 | — | %0,4 | 28 Ara 2018 |
- CVE-2018-2037741Planlayın
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to
KritikCVSS 9,8Kavram kanıtıEPSS %8orange · arv7519rw22 livebox 2.1 firmware23 Ara 2018
- CVE-2018-1837539İzleyin
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the
KritikCVSS 9,8İstismar yokEPSS %1orange · airbox firmware15 Eki 2018
- CVE-2014-315036İzleyin
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive
YüksekCVSS 8,8İstismar yokEPSS %2orange · livebox 1.1 firmware15 Kas 2017
- CVE-2018-2057736İzleyin
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe
KritikCVSS 9,1İstismar yokEPSS %1orange · arv7519rw22 livebox 2.1 firmware28 Ara 2018
- CVE-2018-1837630İzleyin
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices
YüksekCVSS 7,5İstismar yokEPSS %2orange · airbox firmware15 Eki 2018
- CVE-2018-2057530İzleyin
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.
YüksekCVSS 7,5İstismar yokEPSS %1orange · arv7519rw22 livebox 2.1 firmware28 Ara 2018
- CVE-2018-1837730İzleyin
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login
YüksekCVSS 7,5İstismar yokEPSS %1orange · airbox firmware15 Eki 2018
- CVE-2018-2057621İzleyin
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone cal
OrtaCVSS 5,4İstismar yokEPSS %0orange · arv7519rw22 livebox 2.1 firmware28 Ara 2018