VYPR
Vendor

Siklu

Products
6
CVEs
8
Across products
10
Status
Private

Products

6

Recent CVEs

8
  • CVE-2025-57174CriSep 15, 2025
    risk 0.67cvss 9.8epss 0.01

    An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary. These keys are…

  • CVE-2022-47036CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in…

  • CVE-2017-7318CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.04

    Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.

  • CVE-2016-10308CriMar 30, 2017
    risk 0.64cvss 9.8epss 0.03

    Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded…

  • CVE-2024-58300HigDec 11, 2025
    risk 0.57cvss epss 0.00

    Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and…

  • CVE-2025-57176MedSep 15, 2025
    risk 0.45cvss 6.5epss 0.00

    On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only)…

  • CVE-2025-57175MedApr 8, 2026
    risk 0.42cvss 6.4epss 0.00

    Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.

  • CVE-2022-47037Mar 18, 2024
    risk 0.00cvss epss 0.01

    Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.