Vulnerability Description
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gotrango | Apex Plus Firmware | <= 3.2.0 |
| Gotrango | Apex Plus | - |
| Gotrango | Apex Firmware | <= 2.1.1 |
| Gotrango | Apex | - |
| Gotrango | Apex Lynx Firmware | <= 1.2.3 |
| Gotrango | Apex Lynx | - |
| Gotrango | Apex Orion Firmware | <= 1.2.3 |
| Gotrango | Apex Orion | - |
| Gotrango | Giga Firmware | <= 2.6.1 |
| Gotrango | Giga | - |
| Gotrango | Giga Lynx Firmware | <= 1.2.3 |
| Gotrango | Giga Lynx | - |
| Gotrango | Giga Orion Firmware | <= 1.2.3 |
| Gotrango | Giga Orion | - |
| Gotrango | Giga Plus Firmware | <= 3.2.3 |
| Gotrango | Giga Plus | - |
| Gotrango | Giga Pro Firmware | <= 1.4.1 |
| Gotrango | Giga Pro | - |
| Gotrango | Stratalink Pro Firmware | - |
| Gotrango | Stratalink Pro | - |
Related Weaknesses (CWE)
References
- http://blog.iancaling.com/post/153011925478ExploitThird Party Advisory
- http://blog.iancaling.com/post/153011925478ExploitThird Party Advisory
FAQ
What is CVE-2016-10305?
CVE-2016-10305 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices h...
How severe is CVE-2016-10305?
CVE-2016-10305 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10305?
Check the references section above for vendor advisories and patch information. Affected products include: Gotrango Apex Plus Firmware, Gotrango Apex Plus, Gotrango Apex Firmware, Gotrango Apex, Gotrango Apex Lynx Firmware.