Vulnerabilities · 124 days ago

ROX Firmware Hides a Long CVE Backlog

The real issue is not one Siemens bug. ROX firmware before V2.17.1 carries a backlog of third-party flaws, so one appliance version can sit on top of years of latent exposure instead of a single fixable issue. That breaks the usual per-CVE patch mindset for industrial edge gear.

CISA and Siemens now flag multiple CVEs across RUGGEDCOM ROX MX5000, MX5000RE, RX1400, and related ROX models. The advisory covers 35 CVEs from 2019 through 2025, including file-read and root-privilege command-execution issues, and Siemens says to update to V2.17.1 or later.

CVEs in this update

35 CVEs

16 critical · 10 high · 9 medium · 0 low

0 in CISA KEV · 19 with EPSS above 1%

Highest severity: CVE-2019-14192 · 9.8 CRITICAL

Highest EPSS: CVE-2019-14192 · 2.7%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-15

Editions

Related stories