Vulnerabilities · 59 days ago

Siemens OT Switches Can Keep Root After Reboot

A compromised ROX II switch can stop being a network device and become a durable root foothold inside the control plane. The first flaw can expose sensitive config, password hashes, and private keys; the second can turn attacker-controlled input into root commands; the third can write malicious commands into the root cron table so access survives reboots.

The chain covers three zero-days: CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949. Siemens says affected ROX II and Ruggedcom Rox devices running versions before V2.17.1 should be updated to that firmware, because patching only the initial bug does not undo a switch that may already be holding keys or persistence.

CVE-2025-40949

NVD KEV

CVSS 9.1 CRITICAL: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.7% (48th percentile).

CVE-2025-40947

NVD KEV

CVSS 7.5 HIGH: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.5% (42nd percentile).

CVE-2025-40948

NVD KEV

CVSS 6.8 MEDIUM: a vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All… EPSS 0.4% (32nd percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-07-18

Editions

Related stories