9.8
CVSSv3

CVE-2018-18375

Published: 16/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows malicious users to extract APN data (name, number, username, and password) via the rand parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

orange airbox_firmware y858_fl_01.16_04

Github Repositories

AirBoxAPNLeak Proof of Concept of AirBoxAPNLeak Vulnerability CVE-2018-18375 How to use AirBoxAPNLeakpy python AirBoxAPNLeakpy -ip 19216811 APN NAME, NUMBER ,PASSWORD, USERNAME How it works AirBox has hidden webpage 19216811/goform/getProfileList?rand= which prints detailed APN info It can be used to steal external ip addresses Router information Router: AirBo