Orange's vulnerability footprint centers on a narrow range of residential networking and access products, including Livebox and Airbox devices that serve as customer-premises equipment for broadband connectivity. The durable signal is a concentration of web-interface and authentication weaknesses—cross-site request forgery, sensitive-information exposure, improper input validation, and missing authorization—that are endemic to embedded management interfaces with limited security oversight. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the trust boundary these devices occupy in home and small-business networks; live exploitation and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Orange over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20377CRITICAL Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equal | Dec 23, 2018 | 9.8 | 36 | NO | NO |
CVE-2018-18375CRITICAL goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter. | Oct 16, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-20577CRITICAL Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is | Dec 28, 2018 | 9.1 | 28 | NO | NO |
CVE-2018-20575HIGH Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5 | Dec 28, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-18377HIGH goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentia | Oct 16, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-18376HIGH goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses | Oct 16, 2018 | 7.5 | 24 | NO | NO |
CVE-2014-3150HIGH Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript. | Nov 15, 2017 | 8.8 | 22 | NO | NO |
CVE-2018-20576MEDIUM Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone nu | Dec 28, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Orange.
Media articles that mention a CVE ID that affects a product developed by Orange — matched by CVE ID, not by vendor name.