CVE-2025-57176
Last modified
CVE-2025-57176 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-57176?
How severe is CVE-2025-57176?
How do I fix CVE-2025-57176?
Are you affected by CVE-2025-57176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
