CVE-2025-40948
Ruggedcom Rox contains an improper access control vulnerability that could allow an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Ruggedcom Rox are affected: RUGGEDCOM ROX MX5000 vers:intdot/RUGGEDCOM ROX MX5000RE vers:intdot/RUGGEDCOM ROX RX1400 vers:intdot/RUGGEDCOM ROX RX1500 vers:intdot/RUGGEDCOM ROX RX1501 vers:intdot/RUGGEDCOM ROX RX1510 vers:intdot/RUGGEDCOM ROX RX1511 vers:intdot/RUGGEDCOM ROX RX1512 vers:intdot/RUGGEDCOM ROX RX1524 vers:intdot/RUGGEDCOM ROX RX1536 vers:intdot/RUGGEDCOM ROX RX5000 vers:intdot/ CVSS Vendor Equipment Vulnerabilities v3 6.8 Siemens Siemens Ruggedcom Rox Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.05% · 15.8th percentile
Risk Scores
Timeline
- May 19, 2025 PoC Published
- May 12, 2026 CVE Published
- May 13, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-02 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-134-02.json advisory
- https://www.cve.org/CVERecord?id=CVE-2025-40948 technical
- https://support.industry.siemens.com/cs/ww/en/view/110002017/ vendor
- https://cwe.mitre.org/data/definitions/88.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N technical