CVE-2025-40948: stato di sfruttamento e disponibilità della patch
CVE-2025-40948 · CVSS 6.8 MEDIUM · EPSS <1%
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX1536 (All versions < V2.17.1), RUGGEDCOM ROX RX5000 (All versions < V2.17.1). Affected devices do not properly validate input in the web server's JSON-RPC interface.
This could allow an authenticated remote attacker to read arbitrary files from the underlying operating system's filesystem with root privileges.
CVE-2025-40948 viene sfruttato?
- Non è nel catalogo CISA KEV.
- EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al <1%.
- Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.
Esiste una patch?
Nessun identificativo di patch registrato qui.
Cosa ha pubblicato PlainSec su CVE-2025-40948
Fonti primarie
Cosa questa scheda non dice
- Nessun dato sui pacchetti interessati.
- Nessun identificativo di patch.
KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-11.