Junglewise Threat Intelligence

CVE-2025-40833: Siemens Industrial Devices null pointer dereference in IPv4 stack

CVE-2025-40833 · Severity: high · CVSS 7.5 · Published 2026-05-12

Vendors: Siemens.

Executive brief

A variety of Siemens industrial networking devices, including SCALANCE and RUGGEDCOM routers and gateways, are vulnerable to a flaw that can be triggered by malicious network traffic. An attacker can send specially crafted IPv4 requests to crash the device, causing a total loss of connectivity and industrial communication. Recovering from this state requires a manual physical restart of the hardware, which may disrupt factory operations or remote infrastructure.

Technical details

A null pointer dereference vulnerability (CWE-476) exists in the IPv4 stack of several Siemens industrial communication products. An unauthenticated remote attacker can trigger this vulnerability by sending specially crafted IPv4 requests over the network. Successful exploitation causes the device to crash and enter a denial-of-service (DoS) state that cannot be recovered automatically; a manual power cycle or restart is required. Siemens has released firmware version V8.3 for SCALANCE and RUGGEDCOM families to address this, though some products like IE/PB LINK HA currently have no planned fix.

Affected products

  • Siemens IE/PB LINK HA All versions
  • Siemens IE/PB link PN IO All versions
  • Siemens RUGGEDCOM RM1224 LTE(4G) EU All versions < V8.3
  • Siemens RUGGEDCOM RM1224 LTE(4G) NAM All versions < V8.3
  • Siemens SCALANCE M804PB All versions < V8.3
  • Siemens SCALANCE M812-1 ADSL-Router All versions < V8.3
  • Siemens SCALANCE M816-1 ADSL-Router All versions < V8.3
  • Siemens SCALANCE M826-2 SHDSL-Router All versions < V8.3
  • Siemens SCALANCE M874-2 All versions < V8.3
  • Siemens SCALANCE M874-3 3G-Router (CN) All versions < V8.3
  • Siemens SCALANCE M876-3 All versions < V8.3
  • Siemens SCALANCE M876-4 All versions < V8.3
  • Siemens SCALANCE MUM853-1 All versions < V8.3
  • Siemens SCALANCE MUM856-1 All versions < V8.3

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-07-14: other: Last update to advisory V1.1

References

Related threats