CVE-2025-40949
CVSS 9.1 CRITICAL: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.7% (48º percentile).
Vulnerabilità · 73 giorni fa
Un ROX II compromesso non resta un guasto di rete: può diventare un punto d'appoggio root duraturo dentro la rete industriale. La lettura standard “patchare l'appliance” non coglie che la catena può prima aprire file sensibili e chiavi, poi lasciare dentro un accesso che sopravvive ai reboot.
Unit 42 e Siemens descrivono tre zero-day collegati su Siemens ROX II / Ruggedcom Rox: CVE-2025-40948 per la lettura arbitraria di file, CVE-2025-40947 per command injection con privilegi root e CVE-2025-40949 per l'iniezione nella root cron table con persistenza. Siemens ha corretto le versioni precedenti a V2.17.1 tramite gli advisory SSA-973901, SSA-078743 e SSA-081142.
Per chi opera in OT, il punto non è solo chiudere la falla iniziale: se il device è stato toccato, può aver già esposto configurazioni, password hash e chiavi private, e può restare un insider permanente sul control plane.
CVSS 9.1 CRITICAL: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.7% (48º percentile).
CVSS 7.5 HIGH: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.5% (42º percentile).
CVSS 6.8 MEDIUM: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.4% (32º percentile).
1 fonte che coprono questa storia
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.
Part of the PlainSec briefing for 2026-07-18