CVE-2018-18377 describes an improper authorization vulnerability in the goform/setReset function of Orange AirBox Y858_FL_01.16_04 devices, allowing an unauthenticated attacker to remotely trigger a factory reset. This reset enables access using default admin credentials, posing a high risk with a CVSS score of 7.5. While the attack complexity is low and no user interaction is required, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability shows minimal community discussion or media coverage. Despite its potential impact, it is not listed in CISA's KEV catalog and is not considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
y858_fl_01.16_04CPE matchmatch criteria | cpe:2.3:o:orange:airbox_firmware:y858_fl_01.16_04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.