You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-40947
About this tag
CVE-2025-40947 is an authenticated remote command-injection vulnerability affecting Siemens RUGGEDCOM ROX firmware versions before 2.17.1. Discovered in the feature key installation process, the flaw impacts multiple industrial devices including MX5000, RX1400, and RX1500 series. Siemens disclosed the issue on May 12, 2026, with CISA republishing the advisory on May 14. While not a remotely exploitable internet-facing bug, it poses a significant risk in flat or poorly segmented OT networks where an authenticated attacker could gain privileged access. The recommended mitigation is updating to ROX 2.17.1 or later. This tag covers discussions, advisories, and patching guidance for CVE-2025-40947.
Siemens disclosed on May 12, 2026, that RUGGEDCOM ROX versions before 2.17.1 contain CVE-2025-40947, an authenticated remote command-injection flaw in the feature key installation process affecting MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, and RX5000...