CVE-2025-57174 affects Siklu Communications Etherhaul 8010TX and 1200FX devices running firmware 7.4.0 through 10.7.3, and possibly other earlier or related Etherhaul devices sharing the same firmware. The issue is in the rfpiped service exposed on TCP port 555. That service relies on static AES encryption keys hardcoded in the binary, and the same keys are reused across devices. Because an attacker can recover or otherwise obtain these universal keys, they can craft correctly encrypted packets accepted by the service and trigger arbitrary command execution without authentication. The issue is described as a failed patch for CVE-2017-7318, indicating the underlying design flaw was not fully remediated.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit for CVE-2025-57174, targeting Siklu EtherHaul Series devices (such as EH-8010 and EH-1200) running firmware versions 7.4.0 through 10.7.3. The exploit leverages an unauthenticated remote command execution vulnerability by connecting to the device on TCP port 555 and sending specially crafted, AES-encrypted messages. The main script, 'CVE-2025-57174.py', allows the attacker to specify a target IP address and an arbitrary command to execute on the device. The exploit handles the protocol's encryption and message formatting, and can optionally print the command's output. The README provides usage instructions and an example output, confirming successful exploitation. No hardcoded IPs or credentials are present; the exploit is fully operational and requires only network access to a vulnerable device.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.