[FD] Siklu EtherHaul Hidden ‘root’ Account

2016-06-15 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/145309944453/ Vendor: = www.siklu.com/ Product: == -EtherHaul EH-1200F/FX/TX, EH-2200F/FX, EH-600T/TL -EtherHaul EH-1200/TL Vulnerability Type

[FD] Authentication bypass in Ceragon FibeAir IP-10 web interface (<7.2.0)

2016-06-16 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com Vendor: = www.ceragon.com Product: == -FibeAir IP-10 Vulnerability Type: === Default Root Account CVE Reference: == N/A Vulnerability Details: = Ceragon FibeAir

[FD] Trango Systems hidden default root login (all models)

2016-11-11 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/153011925478/ Vendor: = www.trangosys.com Products: == All models. Newer versions use a different password. Vulnerability Type: === Default Root

[FD] Trango Altum AC600 Default root Login

2017-01-06 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/155395764003 Vendor: = https://www.trangosys.com/ Product: == -Altum AC600 Vulnerability Details: = Trango Altum AC600′s have a default root login

[FD] Siklu EtherHaul Unauthenticated Remote Command Execution Vulnerability (<7.4.0)

2017-02-21 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/155127766533 Vendor: = https://www.siklu.com/ Product: == -Siklu EtherHaul (EH-*) Vulnerability Details: = Siklu EtherHaul devices are vulnerable

[FD] DragonWave Horizon Hard-coded Credentials Vulnerability (multiple versions)

2017-04-07 Thread Ian Ling
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/159276197313 Vendor: = http://www.dragonwaveinc.com/ Product: == -DragonWave Horizon Vulnerability Details: = DragonWave Horizon wireless radios

[FD] Mimosa Wireless Radios - RCE, DoS, and Local File Disclosure Vulnerabilities

2017-05-15 Thread Ian Ling via Fulldisclosure
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/160596244178 Vendor: = http://mimosa.co Products: == Access Points (e.g. A5) <2.2.3 Client Radios (e.g. C5) <=2.2.3 Backhaul Radios (e.g. B5) <=2.2.3 Vuln

[FD] Ceragon FibeAir IP-10 Hidden User Backdoor

2017-05-19 Thread Ian Ling via Fulldisclosure
[+] Credits: Ian Ling [+] Website: iancaling.com [+] Source: http://blog.iancaling.com/post/160817658078 Vendor: = https://www.ceragon.com Products: == Ceragon FibeAir IP-10 (<=7.2.0) (latest version) Vulnerability Types: === Hidden U