CVE-2025-63292
中文标题:
(暂无数据)
英文标题:
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–...
漏洞描述
中文描述:
(暂无数据)
英文描述:
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over the `FreeWifi_secure` network. During the EAP-Response/Identity exchange, the subscriber's full Network Access Identifier (NAI), which embeds the raw IMSI, is transmitted without encryption, tunneling, or pseudonymization. An attacker located within Wi-Fi range (~100 meters) can passively capture these frames without requiring user interaction or elevated privileges. The disclosed IMSI enables device tracking, subscriber correlation, and long-term monitoring of user presence near any broadcasting Freebox device. The vendor acknowledged the vulnerability, and the `FreeWifi_secure` service is planned for full deactivation by 1 October 2025.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| freebox | v5_hd_firmware | * | - | - |
cpe:2.3:o:freebox:v5_hd_firmware:*:*:*:*:*:*:*:*
|
| freebox | v5_crystal_firmware | * | - | - |
cpe:2.3:o:freebox:v5_crystal_firmware:*:*:*:*:*:*:*:*
|
| freebox | v6_revolution_firmware | * | - | - |
cpe:2.3:o:freebox:v6_revolution_firmware:*:*:*:*:*:*:*:*
|
| freebox | mini_4k_firmware | * | - | - |
cpe:2.3:o:freebox:mini_4k_firmware:*:*:*:*:*:*:*:*
|
| freebox | one_firmware | * | - | - |
cpe:2.3:o:freebox:one_firmware:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
LOWCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-63292 |
2025-11-19 04:05:45 | 2026-01-12 02:12:15 |
| NVD | nvd_CVE-2025-63292 |
2025-11-19 04:07:44 | 2026-01-12 02:27:58 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 0 -> 5
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']