Critical Vulnerability in Ceragon's MultiHaul and EtherHaul Devices
Basically, some Ceragon devices can be hacked to upload harmful files easily.
A critical vulnerability has been found in Ceragon's MultiHaul and EtherHaul devices, allowing unauthorized file uploads. If you're using these devices, your network could be at risk. Ceragon has issued firmware updates to fix the issue, so don't delay in securing your equipment.
What Happened
A serious vulnerability has been discovered in Ceragon's MultiHaul and EtherHaul series devices. This flaw allows unauthorized users to upload any file to the devices, which could lead to significant security breaches. The issue affects multiple models, including the MultiHaul MH-B100-CCS and various EtherHaul models, making it a widespread concern for users worldwide.
The vulnerability, identified as CVE-2025-57176?, stems from a lack of authentication in the rfpiped service? running on TCP port 555?. This means that attackers can send files to any writable location on the devices without needing a password or any form of verification. The file upload process uses weak encryption?, leaving sensitive data exposed during transmission.
Why Should You Care
If you own or manage any of the affected Ceragon devices, this vulnerability could put your network at risk. Imagine leaving your front door unlocked — that's essentially what this flaw does for your equipment. Without proper security measures, hackers could exploit this vulnerability to gain control over your devices, potentially leading to data breaches or service disruptions.
In today’s digital landscape, your devices are like the keys to your home. If someone can upload harmful files, they could manipulate your network, steal sensitive information, or even disrupt your services. It’s crucial to take this threat seriously and act swiftly to protect your infrastructure.
What's Being Done
Ceragon has acknowledged the issue and released software updates to address the vulnerability. Here’s what you should do if you’re affected:
- Install firmware version R2.4.0 for MultiHaul models.
- Update to firmware version R10.8.1 for the EH-8010FX model.
- For other EtherHaul models, install firmware version R7.7.12.
Additionally, Ceragon recommends following these security practices:
- Use private management IP addresses? only.
- Ensure your devices are behind firewalls? and access control lists?.
- Avoid public exposure of management IP addresses.
Experts are monitoring the situation closely, especially for any potential exploits that could arise from this vulnerability. Stay vigilant and keep your devices updated to safeguard your network.
CISA Advisories