VYPR
Vendor

Orange

Products
6
CVEs
10
Across products
10
Status
Private

Products

6

Recent CVEs

10
  • CVE-2018-20377CriDec 23, 2018
    risk 0.64cvss 9.8epss 0.08

    Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware…

  • CVE-2018-18375CriOct 16, 2018
    risk 0.64cvss 9.8epss 0.01

    goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.

  • CVE-2018-20577CriDec 28, 2018
    risk 0.59cvss 9.1epss 0.01

    Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and…

  • CVE-2014-3150HigNov 15, 2017
    risk 0.57cvss 8.8epss 0.02

    Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.

  • CVE-2018-20575HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.01

    Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.

  • CVE-2018-18377HigOct 16, 2018
    risk 0.49cvss 7.5epss 0.01

    goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.

  • CVE-2018-18376HigOct 16, 2018
    risk 0.49cvss 7.5epss 0.02

    goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.

  • CVE-2026-1808MedFeb 6, 2026
    risk 0.42cvss 6.4epss 0.00

    The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output…

  • CVE-2018-20576MedDec 28, 2018
    risk 0.35cvss 5.4epss 0.00

    Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware…

  • CVE-2001-0647Aug 6, 2001
    risk 0.03cvss epss 0.05

    Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.