CVE-2016-10308
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
Affected (2)
Products: Siklu: Etherhaul Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.7.0 |
| Running on/with | Platform Versions |
|---|---|
Siklu Etherhaul 5500fd | All versions |
Siklu Etherhaul 500tx | All versions |
Siklu Etherhaul 60ghz V Band Radio | All versions |
Siklu Etherhaul 70/80ghz Gigabit Radio | All versions |
Siklu Etherhaul 70/80ghz Multi Gigabit E Band Radio | All versions |
Siklu Etherhaul 70ghz E Band Radio | All versions |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.