10

CVE-2016-10307

Exploit
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gotrango ≫ Apex Lynx Firmware Version 2.0
   Gotrango ≫ Apex Lynx Version -
Gotrango ≫ Apex Orion Firmware Version 2.0
   Gotrango ≫ Apex Orion Version -
Gotrango ≫ Giga Lynx Firmware Version 2.0
   Gotrango ≫ Giga Lynx Version -
Gotrango ≫ Giga Orion Firmware Version 2.0
   Gotrango ≫ Giga Orion Version -
Gotrango ≫ Stratalink Firmware Version <= 3.0
   Gotrango ≫ Stratalink Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.43% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

http://blog.iancaling.com/post/153011925478
Third Party Advisory
Exploit
http://www.securityfocus.com/bid/97242
Third Party Advisory
VDB Entry