peter bassill · operator
$ cve CVE-2016-10308 JSON

CVE-2016-10308

9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.96% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2017-03-30
Last modified2026-06-17

Affected (7)

VendorProduct
sikluetherhaul 500tx
sikluetherhaul 60ghz v-band radio
sikluetherhaul 70\/80ghz gigabit radio
sikluetherhaul 70\/80ghz multi-gigabit e-band radio
sikluetherhaul 70ghz e-band radio
sikluetherhaul firmware
sikluetherhaul-5500fd

References

→ the Explorer  ·  watch your stack  ·  NVD