CVE-2016-10115: Critical severity netgear arlo base station firmware vulnerability
NETGEAR Arlo base stations with firmware 1.7.56178 and earlier, Arlo Q devices with firmware 1.8.05551 and earlier, and Arlo Q Plus devices with firmware 1.8.16094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory configuration.
Affected Software
Event History
Frequently Asked Questions
What are the affected devices for CVE-2016-10115?
The affected devices include NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier.
What is the severity of CVE-2016-10115?
CVE-2016-10115 is considered a high-severity vulnerability due to the use of default credentials.
How do I fix CVE-2016-10115?
To fix CVE-2016-10115, change the default password from '12345678' to a strong, unique password after a factory reset.
What risks does CVE-2016-10115 pose?
CVE-2016-10115 poses a risk of unauthorized access to the device, allowing remote attackers to control the device.
Is there a patch available for CVE-2016-10115?
Yes, updating the firmware of the affected NETGEAR devices to the latest version addresses the vulnerability.