Description
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-1490 | Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it. |
References
| Link | Providers |
|---|---|
| http://blog.iancaling.com/post/153011925478 |
|
History
No history.
Subscriptions
Gotrango
Subscribe
Apex
Subscribe
Apex Firmware
Subscribe
Apex Lynx
Subscribe
Apex Lynx Firmware
Subscribe
Apex Orion
Subscribe
Apex Orion Firmware
Subscribe
Apex Plus
Subscribe
Apex Plus Firmware
Subscribe
Giga
Subscribe
Giga Firmware
Subscribe
Giga Lynx
Subscribe
Giga Lynx Firmware
Subscribe
Giga Orion
Subscribe
Giga Orion Firmware
Subscribe
Giga Plus
Subscribe
Giga Plus Firmware
Subscribe
Giga Pro
Subscribe
Giga Pro Firmware
Subscribe
Stratalink
Subscribe
Stratalink Firmware
Subscribe
Stratalink Pro
Subscribe
Stratalink Pro Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T22:09:40.209Z
Reserved: 2017-03-29T00:00:00.000Z
Link: CVE-2016-10305
No data.
Status : Deferred
Published: 2017-03-30T07:59:00.143
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-10305
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD