CVE-2022-47036

CRITICAL

Siklu TG Terragraph <2.1.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0052
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Published Mar 18, 2024
Tracked Since Feb 18, 2026