CRITICAL · 9.8

CVE-2016-10308

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SS...

Vulnerability Description

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SikluEtherhaul Firmware<= 3.7.0
SikluEtherhaul-5500Fd-
SikluEtherhaul 500Tx-
SikluEtherhaul 60Ghz V-Band Radio-
SikluEtherhaul 70\/80Ghz Gigabit Radio-
SikluEtherhaul 70\/80Ghz Multi-Gigabit E-Band Radio-
SikluEtherhaul 70Ghz E-Band Radio-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-10308?

CVE-2016-10308 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SS...

How severe is CVE-2016-10308?

CVE-2016-10308 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-10308?

Check the references section above for vendor advisories and patch information. Affected products include: Siklu Etherhaul Firmware, Siklu Etherhaul-5500Fd, Siklu Etherhaul 500Tx, Siklu Etherhaul 60Ghz V-Band Radio, Siklu Etherhaul 70\/80Ghz Gigabit Radio.