VYPR

Etherhaul Firmware

by Siklu

CVEs (2)

  • CVE-2017-7318CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.04

    Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.

  • CVE-2016-10308CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.03

    Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded…