CVE-2025-40949
CVSS 9.1 CRITICAL: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.7% (48th percentile).
Vulnerabilities & Exploits · Zero-Day Exploit
A compromised ROX II switch can stop being a network device and become a durable root foothold inside the control plane. The first flaw can expose sensitive config, password hashes, and private keys; the second can turn attacker-controlled input into root commands; the third can write malicious commands into the root cron table so access survives reboots.
The chain covers three zero-days: CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949. Siemens says affected ROX II and Ruggedcom Rox devices running versions before V2.17.1 should be updated to that firmware, because patching only the initial bug does not undo a switch that may already be holding keys or persistence.
1 source · Jul 17
CVSS 9.1 CRITICAL: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.7% (48th percentile).
CVSS 7.5 HIGH: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.5% (42nd percentile).
CVSS 6.8 MEDIUM: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.4% (32nd percentile).
Unit 42
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.
originalPart of the PlainSec briefing for 2026-07-17
Every edition of this story: Siemens OT Switches Can Keep Root After Reboot