CVE-2014-9405: Free Freebox OS

Medium severity, CVSS 5.4. EPSS: 1.5% chance of exploitation in the next 30 days.

A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary code.

Affected products

  • Free Freebox OS: version 3.0.2 only

Published 2020-01-06. Last modified 2026-06-17.