ICSA-26-069-04
·
Published 2026-03-10
·
View on CISA ICS-CERT ↗
Ceragon Siklu MultiHaul and EtherHaul Series
CVSS 5.3
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could result in arbitrary file upload to the target equipment.
CVEs (1)
Remediations
- Ceragon has released a software update for the affected models:
- Affected users should install firmware version R2.4.0 for affected MultiHaul models.
- Affected users should install firmware version R10.8.1 for the affected EH-8010FX model.
- Affected users should install firmware version R7.7.12 for other affected EtherHaul models.
- Additionally Ceragon has provided the following security recommendations for mitigating the listed vulnerability. To prevent exposure, management access must follow standard operator security guidelines:
- Management IP addresses must use private subnets (RFC 1918)
- Management networks must be protected by: *-* Firewalls *-* Access Control Lists *-* Network Access Translation / Secure management domains
- Firewalls
- Access Control Lists
- Network Access Translation / Secure management domains
- Public exposure of management IP Addresses is not supported nor recommendedCeragon requests that affected users please verify that all affected radio units:
- Use private management IP addresses only
- Are placed behind internal security controls
- Follow your organization's authentication and access-control policies
- Please visit the Ceragon portal here: https://portal.ceragon.com/ (login required) for further information.
Affected Vendors
Ceragon
Affected Products (15)
Ceragon
·
MultiHaul MH-B100-CCS
<R2.4.0
Ceragon
·
MultiHaul MH-T200-CCC
<R2.4.0
Ceragon
·
MultiHaul MH-T200-CNN
<R2.4.0
Ceragon
·
MultiHaul MH-T201-CNN
<R2.4.0
Ceragon
·
EtherHaul EH-8010FX
<R10.8.1
Ceragon
·
EtherHaul EH-500TX
<R7.7.12
Ceragon
·
EtherHaul EH-600TX
<R7.7.12
Ceragon
·
EtherHaul EH-614TX
<R7.7.12
Ceragon
·
EtherHaul EH-700TX
<R7.7.12
Ceragon
·
EtherHaul EH-710TX
<R7.7.12
Ceragon
·
EtherHaul EH-1200TX
<R7.7.12
Ceragon
·
EtherHaul EH-1200FX
<R7.7.12
Ceragon
·
EtherHaul EH-2200FX
<R7.7.12
Ceragon
·
EtherHaul EH-2500FX
<R7.7.12
Ceragon
·
EtherHaul EH-5500FD
<R7.7.12
Affected Sectors
Communications
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more