The real issue is not one Siemens bug. ROX firmware before V2.17.1 carries a backlog of third-party flaws, so one appliance version can sit on top of years of latent exposure instead of a single fixable issue. That breaks the usual per-CVE patch mindset for industrial edge gear.
CISA and Siemens now flag multiple CVEs across RUGGEDCOM ROX MX5000, MX5000RE, RX1400, and related ROX models. The advisory covers 35 CVEs from 2019 through 2025, including file-read and root-privilege command-execution issues, and Siemens says to update to V2.17.1 or later.