CVE-2018-20377 describes a critical vulnerability in Orange Livebox 00.96.320S devices, specifically affecting the Arcadyan ARV7519RW22-A-L T VR9 1.2 hardware. This flaw allows remote attackers to easily retrieve Wi-Fi credentials via an unauthenticated request to /get_getnetworkconf.cgi on port 8080. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and requires no user interaction or privileges, potentially leading to full system compromise if the admin password matches the Wi-Fi password or is the default. While there is no evidence of active exploitation in the KEV catalog or public exploit frameworks like Metasploit, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
00.96.00.96.609esCPE matchmatch criteria | cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.00.96.609es:*:*:*:*:*:*:* | ||
00.96.00.96.613CPE matchmatch criteria | cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.00.96.613:*:*:*:*:*:*:* | ||
00.96.217CPE matchmatch criteria | cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.217:*:*:*:*:*:*:* | ||
00.96.321sCPE matchmatch criteria | cpe:2.3:o:orange:arv7519rw22_livebox_2.1_firmware:00.96.321s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.