CVE-2016-10308

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/03/2017
Last modified:
20/04/2025

Description

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siklu:etherhaul_firmware:*:*:*:*:*:*:*:* 3.7.0 (including)
cpe:2.3:o:siklu:etherhaul_firmware:6.0:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul-5500fd:-:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul_500tx:-:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul_60ghz_v-band_radio:-:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul_70\/80ghz_gigabit_radio:-:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul_70\/80ghz_multi-gigabit_e-band_radio:-:*:*:*:*:*:*:*
cpe:2.3:h:siklu:etherhaul_70ghz_e-band_radio:-:*:*:*:*:*:*:*