CVE-2015-2874: Lacie LAC9000436U Firmware

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

Affected products

  • Lacie LAC9000436U Firmware: up to and including 2.3.0.014
  • Lacie LAC9000464U Firmware: up to and including 2.3.0.014
  • Seagate Goflex Sattelite: any version
  • Seagate Wireless Mobile Storage: any version
  • Seagate Wireless Plus Mobile Storage: any version

Published 2015-12-31. Last modified 2026-06-17.