VYPR
Critical severity9.8NVD Advisory· Published Dec 23, 2018· Updated Jun 17, 2026

CVE-2018-20377

CVE-2018-20377

Description

Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.00.96.609es:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.00.96.609es:*:*:*:*:*:*:*
    • cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.00.96.613:*:*:*:*:*:*:*
    • cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.217:*:*:*:*:*:*:*
    • cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.321s:*:*:*:*:*:*:*
  • Orange/Liveboxllm-fuzzy
    Range: 00.96.320S

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.