CVE-2018-18375

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
16/10/2018
Last modified:
03/10/2019

Description

goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:orange:airbox_firmware:y858_fl_01.16_04:*:*:*:*:*:*:*
cpe:2.3:h:orange:airbox:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools