← Back

Orange

orange

8 CVEs • 6 products

Products (6)

Click to collapse
Toggle

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Orange
1Arv7519rw22 Livebox 2.1 Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44...Show more
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.Show less
1Orange
1Arv7519rw22 Livebox 2.1 Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11....Show more
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.Show less
1Orange
1Arv7519rw22 Livebox 2.1 Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan...Show more
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.Show less
1Orange
1Arv7519rw22 Livebox 2.1 Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default...Show more
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.Show less
1Orange
1Airbox Firmware
Nov 21, 2024
Oct 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
1Orange
1Airbox Firmware
Nov 21, 2024
Oct 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand para...Show more
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.Show less
1Orange
1Airbox Firmware
Nov 21, 2024
Oct 16, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
1Orange
1Livebox 1.1 Firmware
May 13, 2026
Nov 15, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.