VendorsOrangeairboxany version
Vulnerabilities

Orange AirBox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-18375
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
Published 2018-10-16 · Modified
9.8EPSS 0.013
CVE-2018-18376
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
Published 2018-10-16 · Modified
7.5EPSS 0.015
CVE-2018-18377
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
Published 2018-10-16 · Modified
7.5EPSS 0.009