Ceragon Siklu MultiHaul and EtherHaul Series
Ceragon Networks Siklu MultiHaul and EtherHaul Series microwave antennas contain a critical unauthenticated arbitrary file upload vulnerability (CVE-2025-57176) in the rfpiped service on TCP port 555, affecting multiple device models worldwide. The vulnerability allows attackers to upload files to any writable location with weak encryption and no authentication or path validation, with a public PoC already disclosed.
Summary
Ceragon Networks Siklu MultiHaul and EtherHaul Series microwave antennas contain a critical unauthenticated arbitrary file upload vulnerability (CVE-2025-57176) in the rfpiped service on TCP port 555, affecting multiple device models worldwide. The vulnerability allows attackers to upload files to any writable location with weak encryption and no authentication or path validation, with a public PoC already disclosed.
Indicators of Compromise
- cve — CVE-2025-57176
- mitre_attack — CWE-434