Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-03-30T07:00:00

Updated: 2024-08-06T03:14:42.946Z

Reserved: 2017-03-29T00:00:00

Link: CVE-2016-10308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-03-30T07:59:00.237

Modified: 2017-04-04T15:39:25.820

Link: CVE-2016-10308

cve-icon Redhat

No data.