Filtered by vendor Free Subscriptions
Total 8 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-63292 1 Free 6 Freebox Hd, Freebox Mini, Freebox One and 3 more 2025-11-18 3.5 Low
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over the `FreeWifi_secure` network. During the EAP-Response/Identity exchange, the subscriber's full Network Access Identifier (NAI), which embeds the raw IMSI, is transmitted without encryption, tunneling, or pseudonymization. An attacker located within Wi-Fi range (~100 meters) can passively capture these frames without requiring user interaction or elevated privileges. The disclosed IMSI enables device tracking, subscriber correlation, and long-term monitoring of user presence near any broadcasting Freebox device. The vendor acknowledged the vulnerability, and the `FreeWifi_secure` service is planned for full deactivation by 1 October 2025.
CVE-2020-24377 1 Free 10 Freebox Delta, Freebox Delta Firmware, Freebox Mini and 7 more 2024-11-21 9.6 Critical
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
CVE-2020-24376 1 Free 10 Freebox Delta, Freebox Delta Firmware, Freebox Mini and 7 more 2024-11-21 9.6 Critical
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
CVE-2020-24375 1 Free 3 Freebox Server, Freebox V5, Freebox V5 Firmware 2024-11-21 6.5 Medium
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
CVE-2020-24374 1 Free 2 Freebox Hd, Freebox Hd Firmware 2024-11-21 9.6 Critical
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
CVE-2020-24373 1 Free 10 Freebox Delta, Freebox Delta Firmware, Freebox Mini and 7 more 2024-11-21 8.8 High
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
CVE-2014-9405 1 Free 1 Freebox Os 2024-11-21 5.4 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary code.
CVE-2014-9382 1 Free 1 Freebox Os 2024-11-21 6.5 Medium
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation