← Back

Etherhaul Firmware

etherhaul_firmware

Vendor: Siklu • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siklu
1Etherhaul Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaint...Show more
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.Show less
1Siklu
1Etherhaul Firmware
May 13, 2026
Mar 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's w...Show more
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.Show less