PT-2016-3209 · Trango · Trango Altum Ac600

Published

2016-12-23

·

Updated

2017-04-04

·

CVE-2016-10306

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trango Altum AC600 devices (affected versions not specified)
Description The issue concerns a built-in, hidden root account with a default password of abcd1234. This account can be accessed via SSH and/or TELNET, granting full control over the device by allowing access to the underlying embedded UNIX OS. The exploitation of this issue may enable a remote attacker to gain administrative access to the device's operating system using SSH or Telnet protocol.
Recommendations For Trango Altum AC600 devices, change the default password of the root account to a strong, unique password to prevent unauthorized access. As a temporary workaround, consider disabling SSH and TELNET access to the device until a more secure configuration or patch is available. Restrict access to the device's administrative interface to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02502
CVE-2016-10306

Affected Products

Trango Altum Ac600