Junglewise Threat Intelligence

CVE-2025-57175: Siklu EtherHaul 8010 static root password

CVE-2025-57175 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

Siklu EtherHaul 8010 wireless bridge devices contain a hard-coded root password. An attacker with physical access to the device's serial interface can use this password to gain full administrative control. This allows for the interception of network traffic, modification of device configurations, or the extraction of sensitive encryption keys.

Technical details

The Siklu EtherHaul 8010 (running firmware siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b) contains a static root password (CWE-259) that is shared across devices. This vulnerability was identified via physical teardown and UART serial console access. By connecting to the J7 UART header on the PCB, an attacker can access the Linux-based shell. The static credentials allow for full root-level execution, enabling further exploitation such as intercepting firmware decryption keys passed via stdin to OpenSSL during the upgrade process. While the attack requires physical access to the hardware, it provides a complete compromise of the device's operating system.

Affected products

  • Siklu EtherHaul 8010 firmware siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b

Timeline

  • 2025-04-30: disclosed: Initial researcher write-up published
  • 2026-04-08: advisory: CVE published by MITRE

References