CVE-2016-2310
9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.22% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-06-09 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| ge | multilink firmware |
| ge | multilink ml1200 |
| ge | multilink ml1600 |
| ge | multilink ml2400 |
| ge | multilink ml3000 |
| ge | multilink ml3100 |
| ge | multilink ml800 |
| ge | multilink ml810 |
References
→ the Explorer · watch your stack · NVD