PT-2025-37368 · Siklu Communications · Etherhaul 1200Fx+1

Semaja2

·

Published

2025-09-13

·

Updated

2026-01-22

·

CVE-2025-57174

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Siklu Communications Etherhaul 8010TX and 1200FX devices versions 7.4.0 through 10.7.3
Description An issue exists in the rfpiped service, listening on TCP port 555, which utilizes static AES encryption keys hardcoded within the binary. These keys are consistent across all devices, enabling attackers to construct encrypted packets to execute arbitrary commands without authentication. This is a failed patch for a previously known issue. Other Etherhaul series devices with shared firmware may also be affected.
Recommendations Versions prior to 7.4.0 are recommended. Versions 7.4.0 through 10.7.3 are recommended to be updated.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-57174

Affected Products

Etherhaul 1200Fx
Etherhaul 8010Tx