Vulnerability Details CVE-2018-18376
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-18376
-
cpe:2.3:h:orange:airbox:-
-
cpe:2.3:o:orange:airbox_firmware:y858_fl_01.16_04