A compromised ROX II switch can stop being a network device and become a durable root foothold inside the control plane. The first flaw can expose sensitive config, password hashes, and private keys; the second can turn attacker-controlled input into root commands; the third can write malicious commands into the root cron table so access survives reboots.
The chain covers three zero-days: CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949. Siemens says affected ROX II and Ruggedcom Rox devices running versions before V2.17.1 should be updated to that firmware, because patching only the initial bug does not undo a switch that may already be holding keys or persistence.