Junglewise Threat Intelligence

CVE-2025-57174: Siklu Etherhaul hardcoded keys in rfpiped service remote command execution

CVE-2025-57174 · Severity: critical · CVSS 9.8 · Published 2025-09-15

Executive brief

Siklu Etherhaul wireless bridges, used for high-capacity network connectivity in industries like telecommunications and public safety, contain a critical security flaw. The devices use identical, permanent security keys across all units, which allows an unauthorized person to bypass encryption. An attacker can exploit this to take full control of the device, potentially disrupting network operations or gaining access to sensitive data passing through the bridge.

Technical details

The vulnerability exists in the rfpiped service listening on TCP port 555, which handles inter-device communication. Although encryption was introduced to address a previous vulnerability (CVE-2017-7318), the implementation uses static AES-256 encryption keys and predictable initialization vectors (IVs) hardcoded in the binary. Because these keys are identical across all Etherhaul devices, a remote, unauthenticated attacker can decrypt traffic or craft malicious encrypted packets to execute arbitrary CLI commands. This allows for complete device compromise, including the creation of new administrative users. As of the advisory date, no official patch is available, and mitigation involves blocking TCP port 555 and isolating the management interface.

Affected products

  • Siklu Communications (Ceragon) Etherhaul 8010TX 7.4.0 through 10.7.3
  • Siklu Communications (Ceragon) Etherhaul 1200FX 7.4.0 through 10.7.3
  • Siklu Communications (Ceragon) Etherhaul Series All firmware versions using shared rfpiped service code

Timeline

  • 2025-04-12: other: Initial discovery of the vulnerability
  • 2025-04-16: other: Vendor notified of the issue
  • 2025-08-02: disclosed: Public disclosure by security researcher
  • 2025-09-15: advisory: CVE published to NVD

References