ZeroHour

CVE-2016-10307

PoC
CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

Vendors
gotrango
Products
apex lynx firmware, apex orion firmware, giga lynx firmware, giga orion firmware, stratalink firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.