SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-10308

This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

CRITICAL 9.8EPSS 2.96%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.96% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
siklu/etherhaul firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.