CVE-2016-10308
Estado: ModificadaCrítica (9.8)—
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.96%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-798
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-10308",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-03-30T07:59:00.237",
"references": [
{
"url": "http://blog.iancaling.com/post/145309944453",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/97243",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://blog.iancaling.com/post/145309944453",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/97243",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it."
},
{
"lang": "es",
"value": "Siklu EtherHaul radios en versiones anteriores a 3.7.1 y 6.x en versiones anteriores a 6.9.0 tienen incorporada, una cuenta root oculta, con una contraseña inalterable que es la misma en todos los dispositivos. Esta cuenta es accesible a través de SSH y la interface web del dispositivo y concede el acceso al OS Linux incrustado en el dispositivo, permitiendo un control total sobre él."
}
],
"lastModified": "2026-06-17T00:39:27.187",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siklu:etherhaul_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E5FCA0E-EE0E-423C-9805-DC6F4E8416D1",
"versionEndIncluding": "3.7.0"
},
{
"criteria": "cpe:2.3:o:siklu:etherhaul_firmware:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C6BC2B9-5985-4DD5-93A1-5CD6603F4B21"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siklu:etherhaul-5500fd:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "129AECB7-8446-43D4-8D68-6B889DEB9E8A"
},
{
"criteria": "cpe:2.3:h:siklu:etherhaul_500tx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "06C63B8C-013D-4C6B-9AE0-B93F9B48B7DB"
},
{
"criteria": "cpe:2.3:h:siklu:etherhaul_60ghz_v-band_radio:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "677C7A13-EE9C-4423-A2CB-7A631B03AA32"
},
{
"criteria": "cpe:2.3:h:siklu:etherhaul_70\\/80ghz_gigabit_radio:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B7B64120-E688-4F85-9425-D1F62AE9EB7A"
},
{
"criteria": "cpe:2.3:h:siklu:etherhaul_70\\/80ghz_multi-gigabit_e-band_radio:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6CDAA518-3237-47A6-9C2E-DF1506262939"
},
{
"criteria": "cpe:2.3:h:siklu:etherhaul_70ghz_e-band_radio:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A3970FA0-7CBD-484D-A580-CD4A74C63075"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}