← Back

CVE-2016-10305

nvd nist
Published: Mar 30, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

Affected (11)

11 products
Apex Plus Firmware
Apex Firmware
Apex Lynx Firmware
Apex Orion Firmware
Giga Firmware
Giga Lynx Firmware
Giga Orion Firmware
Giga Plus Firmware
Giga Pro Firmware
Stratalink Pro Firmware
Stratalink Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.2.0
Running on/withPlatform Versions
Gotrango
Apex Plus
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.1.1
Running on/withPlatform Versions
Gotrango
Apex
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.2.3
Running on/withPlatform Versions
Gotrango
Apex Lynx
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.2.3
Running on/withPlatform Versions
Gotrango
Apex Orion
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.6.1
Running on/withPlatform Versions
Gotrango
Giga
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.2.3
Running on/withPlatform Versions
Gotrango
Giga Lynx
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.2.3
Running on/withPlatform Versions
Gotrango
Giga Orion
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.2.3
Running on/withPlatform Versions
Gotrango
Giga Plus
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.4.1
Running on/withPlatform Versions
Gotrango
Giga Pro
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Gotrango
Stratalink Pro
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.2.0
Running on/withPlatform Versions
Gotrango
Stratalink
All versions

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.