CVE-2016-1561 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 74.3% (pctl 99)
Patch early
A public exploit exists.
Description
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 74.26% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-04-21 |
| Last modified | 2026-06-17 |
Affected (16)
| Vendor | Product |
|---|---|
| exagrid | ex10000e |
| exagrid | ex10000e firmware |
| exagrid | ex13000e |
| exagrid | ex13000e firmware |
| exagrid | ex21000e |
| exagrid | ex21000e firmware |
| exagrid | ex3000 |
| exagrid | ex3000 firmware |
| exagrid | ex32000e |
| exagrid | ex32000e firmware |
| exagrid | ex40000e |
| exagrid | ex40000e firmware |
| exagrid | ex5000 |
| exagrid | ex5000 firmware |
| exagrid | ex7000 |
| exagrid | ex7000 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ExaGrid - Known SSH Key and Default Password (Metasploit) | 2016-04-07 |
References
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
- http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html
- http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey
- https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-credentials
→ the Explorer · watch your stack · NVD