CVE-2018-20377: Orange ARV7519RW22 Livebox 2.1 Firmware
Critical severity, CVSS 9.8. EPSS: 7.7% chance of exploitation in the next 30 days.
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
Affected products
- Orange ARV7519RW22 Livebox 2.1 Firmware: version 00.96.00.96.609es only; version 00.96.00.96.613 only; version 00.96.217 only; version 00.96.321s only
Published 2018-12-23. Last modified 2026-06-17.