Security readout for executives and security teams
Plain-English summary
A specific Orange Livebox router firmware exposes an undocumented manual firmware update URI. The record does not show whether attackers can reach it without credentials or whether it has been exploited. Treat this as an inventory and vendor-guidance issue for any still-deployed matching devices.
Executive priority
Prioritize asset discovery and vendor confirmation, not emergency response, unless matching devices are exposed in sensitive or externally reachable environments. Evidence is too incomplete to rate business impact confidently.
Technical view
CVE-2018-20575 identifies /system_firmwarel.stm on Orange Livebox 00.96.320S, related to listed firmware, boot, modem, hardware, and Arcadyan platform details. Sources do not provide CVSS, CWE, authentication requirements, patch status, or confirmed impact beyond the undocumented firmware-update endpoint.
Likely exposure
Exposure appears limited to Orange Livebox 00.96.320S devices matching the listed firmware and hardware identifiers. The source bundle does not establish whether the endpoint is remotely reachable, authenticated, or present on other models.
Exploitation context
The CVE is not listed as KEV, and the provided sources do not document active exploitation. Public reference material names a hidden firmware-update URI, but does not establish exploit prerequisites, reliability, or attacker impact.
Researcher notes
The record is sparse: no CVSS, CWE, vendor fix, authentication detail, or impact statement is supplied. Avoid expanding scope beyond the named Orange Livebox 00.96.320S and listed component versions without additional evidence.
Mitigation direction
- Identify any Orange Livebox 00.96.320S devices in use or managed environments.
- Check Orange or service-provider guidance for firmware updates, replacements, or configuration advice.
- Restrict router administration interfaces to trusted networks where operationally possible.
- Retire or replace matching devices if supported firmware guidance is unavailable.
Validation and detection
- Inventory router model, firmware, boot, modem, and hardware identifiers against the CVE description.
- Confirm whether /system_firmwarel.stm exists only from authorized administrative contexts.
- Review management-interface exposure from untrusted networks without probing beyond authorized validation.
- Document vendor response, firmware status, and compensating controls for each matching device.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-20575 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/zadewg/LIVEBOX-0DAYCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
