Vulnerability record · CVE-2016-1561 · published 21 April 2017
CVE-2016-1561: ExaGrid appliances ship default root SSH authorized key
Exagrid · Ex3000 Firmware
ExaGrid appliances running firmware before 4.8 P26 include a default SSH public key in root's authorized_keys file. Because the matching private key is shared across installations and recoverable from firmware images, anyone who obtains it can log in as root. This is a hardcoded-credential backdoor rather than a memory-safety bug, so it stays exploitable until the key is removed.
Description
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote root access with public exploit tooling and very high EPSS, though it is not in KEV and requires the appliance to be network-reachable.
What it is
ExaGrid appliances running firmware before 4.8 P26 include a default SSH public key in root's authorized_keys file. Because the matching private key is shared across installations and recoverable from firmware images, anyone who obtains it can log in as root. This is a hardcoded-credential backdoor rather than a memory-safety bug, so it stays exploitable until the key is removed.
Impact
An attacker gains interactive root SSH access to the appliance, exposing stored backup data and allowing full control of the device. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.
Attack surface
Reachable over the network via SSH on the appliance; no authentication is required because the attacker authenticates with the known private key. No user interaction is needed, and the vector is AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is 0.74261 (99.5th percentile) and multiple references are tagged Exploit, including a Rapid7 Metasploit module and a Packet Storm advisory, so public exploitation tooling exists.
What to do
- Upgrade appliance firmware to 4.8 P26 or later, which removes the default key.
- Until patched, remove the default public key from /root/.ssh/authorized_keys and audit for any other hardcoded credentials.
- Restrict SSH access to a management network or jump host and block port 22 from untrusted networks.
- Rotate any credentials or data that may have been exposed if compromise is suspected.
Detection
- Review /root/.ssh/authorized_keys on all ExaGrid appliances for the known default key.
- Monitor SSH authentication logs for root logins from unexpected source addresses or at unusual times.
- Alert on SSH connections to appliance management interfaces from outside approved management subnets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey | Third Party Advisory |
| https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-creden | ExploitMitigationThird Party Advisory |
| http://packetstormsecurity.com/files/136634/ExaGrid-Known-SSH-Key-Default-Password.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.rapid7.com/db/modules/exploit/linux/ssh/exagrid_known_privkey | Third Party Advisory |
| https://community.rapid7.com/community/infosec/blog/2016/04/07/r7-2016-04-exagrid-backdoor-ssh-keys-and-hardcoded-creden | ExploitMitigationThird Party Advisory |
Track CVE-2016-1561 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-1561), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.