PT-2025-37370 · Ceragon Networks · Etherhaul+1

Published

2025-09-13

·

Updated

2026-04-15

·

CVE-2025-57176

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ceragon Networks / Siklu Communication EtherHaul series versions 7.4.0 through 10.7.3
Description The rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed.
Recommendations Update to a version later than 10.7.3.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-57176

Affected Products

Etherhaul
Siklu Communication Etherhaul