4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Description
The rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series (8010TX and 1200FX tested) Firmware 7.4.0 through 10.7.3 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed.
Basic Information
ID
CVE-2025-57176
Source
mitre
Published
Sep 15, 2025 at 00:00
Modified
Sep 15, 2025 at 19:14
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
4.3 / 10
AI Severity
MEDIUM
Vendor
Ceragon Networks / Siklu Communication
Product
EtherHaul series
Version
7.4.0,10.7.3