VYPR

EtherHaul 8010

by Siklu

CVEs (4)

  • CVE-2025-57174CriSep 15, 2025
    risk 0.67cvss 9.8epss 0.02

    An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary. These keys are…

  • CVE-2017-7318CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.04

    Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.

  • CVE-2016-10308CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.02

    Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded…

  • CVE-2025-57175MedApr 8, 2026
    risk 0.42cvss 6.4epss 0.00

    Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.