PT-2025-37368 · Siklu Communications · Etherhaul 1200Fx+1
Semaja2
·
Published
2025-09-13
·
Updated
2026-01-22
·
CVE-2025-57174
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Siklu Communications Etherhaul 8010TX and 1200FX devices versions 7.4.0 through 10.7.3
Description
An issue exists in the
rfpiped service, listening on TCP port 555, which utilizes static AES encryption keys hardcoded within the binary. These keys are consistent across all devices, enabling attackers to construct encrypted packets to execute arbitrary commands without authentication. This is a failed patch for a previously known issue. Other Etherhaul series devices with shared firmware may also be affected.Recommendations
Versions prior to 7.4.0 are recommended.
Versions 7.4.0 through 10.7.3 are recommended to be updated.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etherhaul 1200Fx
Etherhaul 8010Tx