7.5
CVSSv3

CVE-2018-18376

Published: 16/10/2018 Updated: 06/12/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote malicious users to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

orange airbox_firmware y858_fl_01.16_04

Github Repositories

AirboxLeak Proof of Concept of AirBoxLeak Vulnerability CVE-2018-18376 How to use AsusLeakpy python AirBoxLeakpy -ip 19216811 IP, HOSTNAME, MAC ADDRESS, CONNECTION TIME How it works AirBox has hidden webpage 19216811/goform/getWlanClientInfo?rand= which prints currently connected devices ip,hostnames,mac addresses and connection time Router information Router: