Description
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
Published: 2017-03-30
Score: 9.8 Critical
EPSS: 2.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-1493 Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
History

No history.

Subscriptions

Siklu Etherhaul-5500fd Etherhaul 500tx Etherhaul 60ghz V-band Radio Etherhaul 70\/80ghz Gigabit Radio Etherhaul 70\/80ghz Multi-gigabit E-band Radio Etherhaul 70ghz E-band Radio Etherhaul Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T03:14:42.946Z

Reserved: 2017-03-29T00:00:00.000Z

Link: CVE-2016-10308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-03-30T07:59:00.237

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-10308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses