Filtered by vendor Free Subscriptions
Filtered by product Freebox Os Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-63292 1 Free 6 Freebox Hd, Freebox Mini, Freebox One and 3 more 2025-11-18 3.5 Low
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over the `FreeWifi_secure` network. During the EAP-Response/Identity exchange, the subscriber's full Network Access Identifier (NAI), which embeds the raw IMSI, is transmitted without encryption, tunneling, or pseudonymization. An attacker located within Wi-Fi range (~100 meters) can passively capture these frames without requiring user interaction or elevated privileges. The disclosed IMSI enables device tracking, subscriber correlation, and long-term monitoring of user presence near any broadcasting Freebox device. The vendor acknowledged the vulnerability, and the `FreeWifi_secure` service is planned for full deactivation by 1 October 2025.
CVE-2014-9405 1 Free 1 Freebox Os 2024-11-21 5.4 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary code.
CVE-2014-9382 1 Free 1 Freebox Os 2024-11-21 6.5 Medium
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation