VYPR

Airbox Firmware

by Orange

CVEs (3)

  • CVE-2018-18375CriOct 16, 2018
    risk 0.64cvss 9.8epss 0.01

    goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.

  • CVE-2018-18377HigOct 16, 2018
    risk 0.49cvss 7.5epss 0.01

    goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.

  • CVE-2018-18376HigOct 16, 2018
    risk 0.49cvss 7.5epss 0.02

    goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.