10

CVE-2016-10305

Exploit
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GotrangoApex Plus Firmware Version <= 3.2.0
   GotrangoApex Plus Version-
GotrangoApex Firmware Version <= 2.1.1
   GotrangoApex Version-
GotrangoApex Lynx Firmware Version <= 1.2.3
   GotrangoApex Lynx Version-
GotrangoApex Orion Firmware Version <= 1.2.3
   GotrangoApex Orion Version-
GotrangoGiga Firmware Version <= 2.6.1
   GotrangoGiga Version-
GotrangoGiga Lynx Firmware Version <= 1.2.3
   GotrangoGiga Lynx Version-
GotrangoGiga Orion Firmware Version <= 1.2.3
   GotrangoGiga Orion Version-
GotrangoGiga Plus Firmware Version <= 3.2.3
   GotrangoGiga Plus Version-
GotrangoGiga Pro Firmware Version <= 1.4.1
   GotrangoGiga Pro Version-
GotrangoStratalink Pro Firmware Version-
   GotrangoStratalink Pro Version-
GotrangoStratalink Firmware Version <= 2.2.0
   GotrangoStratalink Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.58
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.