Vulnerability Description
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Arlo Base Station Firmware | <= 1.7.5_6178 |
| Netgear | Vmb30X0 | - |
| Netgear | Vmk3Xx0 | - |
| Netgear | Vms3Xx0 | - |
| Netgear | Arlo Q Camera Firmware | <= 1.8.0_5551 |
| Netgear | Vmc3040 | - |
| Netgear | Arlo Q Plus Camera Firmware | <= 1.8.1_6094 |
| Netgear | Vmc3040S | - |
Related Weaknesses (CWE)
References
- http://blog.newskysecurity.com/2016/09/factory_reset_vuln_in_netgear_arlo/Third Party Advisory
- http://kb.netgear.com/30731/Arlo-WiFi-Default-Password-Security-VulnerabilityMitigationVendor Advisory
- http://www.securityfocus.com/bid/95265Third Party AdvisoryVDB Entry
- http://blog.newskysecurity.com/2016/09/factory_reset_vuln_in_netgear_arlo/Third Party Advisory
- http://kb.netgear.com/30731/Arlo-WiFi-Default-Password-Security-VulnerabilityMitigationVendor Advisory
- http://www.securityfocus.com/bid/95265Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-10115?
CVE-2016-10115 is a vulnerability with a CVSS score of 9.8 (CRITICAL). NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default passwo...
How severe is CVE-2016-10115?
CVE-2016-10115 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10115?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Arlo Base Station Firmware, Netgear Vmb30X0, Netgear Vmk3Xx0, Netgear Vms3Xx0, Netgear Arlo Q Camera Firmware.