CVE-2024-58300 Details
Description
Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attackers to retrieve randomly generated credentials via a network request. Attackers can send a specific hex-encoded command to port 12777 to obtain username and password, enabling direct SSH access to the device.
A vulnerability exists in Siklu MultiHaul TG series devices prior to version 2.0.0, allowing remote attackers to access randomly generated credentials without authentication. By sending a specific hex-encoded command to port 12777, attackers can retrieve usernames and passwords, which facilitate direct SSH access to the device.
Users are advised to update to Siklu MultiHaul TG series version 2.0.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 11, 2025CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siklu.com/ | [email protected] | Vendor |
| https://www.exploit-db.com/exploits/51932 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/siklu-multihaul-tg-series-unauthenticated-credential-disclosure-vulnerability | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siklu MultiHaul TG | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 11, 2025 | New CVE Received | [email protected] |
Volerion