CVE-2016-10308
9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.96% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-03-30 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| siklu | etherhaul 500tx |
| siklu | etherhaul 60ghz v-band radio |
| siklu | etherhaul 70\/80ghz gigabit radio |
| siklu | etherhaul 70\/80ghz multi-gigabit e-band radio |
| siklu | etherhaul 70ghz e-band radio |
| siklu | etherhaul firmware |
| siklu | etherhaul-5500fd |
References
→ the Explorer · watch your stack · NVD