CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87826  CVE-2016-10305  Candidate  Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87827  CVE-2016-10306  Candidate  Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87828  CVE-2016-10307  Candidate  Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87829  CVE-2016-10308  Candidate  Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device"s web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87830  CVE-2016-10309  Candidate  In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.  Assigned (20170329)  None (candidate not yet proposed)    View

Page 20238 of 20943, showing 5 records out of 104715 total, starting on record 101186, ending on 101190

Actions