Siklu Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Siklu products.
Products
- tg_terragraph2 vulnerabilities
- EtherHaul 80101 vulnerability
- MultiHaul TG series1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-57175MEDIUM | Generated title:Siklu EtherHaul 8010 Static Root PasswordSiklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. CWE-259Apr 8, 2026 | CVSS6.4v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58300HIGH | Siklu MultiHaul TG Series < 2.0.0 Unauthenticated Credential Disclosure VulnerabilitySiklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and password, enabling direct SSH access to the device. CWE-306Dec 11, 2025 | CVSS8.7v4.0 | EPSS0.404% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47037HIGH | Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. | CVSS7.5v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47036CRITICAL | Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later. CWE-284Mar 18, 2024 | CVSS9.8v3.1 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |