Back to Database
Status published
High
CVE-2018-18377
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset...
Vulnerability Description
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18377
Credits & Attribution
No credits recorded in the NVD database.
References
More from orange
View All →CVE-2018-20577
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and...
Critical
9.1
CVE-2018-20576
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading...
Medium
5.4
CVE-2018-20575
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for...
High
7.5
CVE-2018-20377
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi...
Critical
9.8
CVE-2018-18376
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover...
High
7.5
Affected Vendor
orange
View all reports →Affected Software
airbox firmware
Vulnerable Versions:
y858_fl_01.16_04
Timeline
Official Publish:
October 16th, 2018
Last Modified:
September 16th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.