Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Gotrango
Subscribe
|
Apex
Subscribe
Apex Firmware
Subscribe
Apex Lynx
Subscribe
Apex Lynx Firmware
Subscribe
Apex Orion
Subscribe
Apex Orion Firmware
Subscribe
Apex Plus
Subscribe
Apex Plus Firmware
Subscribe
Giga
Subscribe
Giga Firmware
Subscribe
Giga Lynx
Subscribe
Giga Lynx Firmware
Subscribe
Giga Orion
Subscribe
Giga Orion Firmware
Subscribe
Giga Plus
Subscribe
Giga Plus Firmware
Subscribe
Giga Pro
Subscribe
Giga Pro Firmware
Subscribe
Stratalink
Subscribe
Stratalink Firmware
Subscribe
Stratalink Pro
Subscribe
Stratalink Pro Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-1490 | Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://blog.iancaling.com/post/153011925478 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T22:09:40.209Z
Reserved: 2017-03-29T00:00:00Z
Link: CVE-2016-10305
No data.
Status : Deferred
Published: 2017-03-30T07:59:00.143
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-10305
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD