CVE-2016-10305
This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- gotrango/apex plus firmware · gotrango/apex firmware · gotrango/apex lynx firmware · gotrango/apex orion firmware · gotrango/giga firmware · gotrango/giga lynx firmware · gotrango/giga orion firmware · gotrango/giga plus firmware · gotrango/giga pro firmware · gotrango/stratalink pro firmware · gotrango/stratalink firmware
- Source
- cve@mitre.org
References
- http://blog.iancaling.com/post/153011925478Exploit, Third Party Advisory
- http://blog.iancaling.com/post/153011925478Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.