CVE-2016-10306
CVE-2016-10306
9.8
CriticalPublished:
Last updated:
Source:cve@mitre.org
Modified
Weakness (CWE)
CVSS Vector
v3.0- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
References
cve@mitre.org
http://blog.iancaling.com/post/153011925478cve@mitre.org
http://blog.iancaling.com/post/155395764003cve@mitre.org
http://www.securityfocus.com/bid/97241af854a3a-2127-422b-91ae-364da2661108
http://blog.iancaling.com/post/153011925478af854a3a-2127-422b-91ae-364da2661108
http://blog.iancaling.com/post/155395764003af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/97241