Vulnerabilities > Orange > Arv7519Rw22 Livebox 2 1 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-12-28 CVE-2018-20576 Cross-Site Request Forgery (CSRF) vulnerability in Orange Arv7519Rw22 Livebox 2.1 Firmware 00.96.320S
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number.
network
low complexity
orange CWE-352
5.4