CVE Vulnerabilities

CVE-2009-3710

Published: Oct 16, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.

Affected Software

NameVendorStart VersionEnd Version
RiosRiorey4.6.6 (including)4.6.6 (including)
RiosRiorey4.7.0 (including)4.7.0 (including)

References