Executive brief
Siemens RUGGEDCOM ROX devices, which are industrial Ethernet switches used in harsh environments like power substations, contain a security vulnerability in their web management interface. An authorized user with high-level permissions could exploit this flaw to access sensitive system files that should normally be protected. This could lead to the exposure of configuration data or other critical system information, potentially compromising the integrity of the industrial network.
Technical details
A vulnerability classified as Improper Neutralization of Argument Delimiters (CWE-88) exists in the JSON-RPC interface of the RUGGEDCOM ROX web server. The issue stems from insufficient validation of user-supplied input, which can be manipulated to perform argument injection. An authenticated remote attacker with high privileges (PR:H) can exploit this to read arbitrary files from the underlying Linux filesystem with root-level access. Siemens has addressed this in version V2.17.1 by improving input validation routines.
Affected products
- Siemens RUGGEDCOM ROX MX5000 < V2.17.1
- Siemens RUGGEDCOM ROX MX5000RE < V2.17.1
- Siemens RUGGEDCOM ROX RX1400 < V2.17.1
- Siemens RUGGEDCOM ROX RX1500 < V2.17.1
- Siemens RUGGEDCOM ROX RX1501 < V2.17.1
- Siemens RUGGEDCOM ROX RX1510 < V2.17.1
- Siemens RUGGEDCOM ROX RX1511 < V2.17.1
- Siemens RUGGEDCOM ROX RX1512 < V2.17.1
- Siemens RUGGEDCOM ROX RX1524 < V2.17.1
- Siemens RUGGEDCOM ROX RX1536 < V2.17.1
- Siemens RUGGEDCOM ROX RX5000 < V2.17.1
Timeline
- 2026-05-12: disclosed
- 2026-05-12: patched
- 2026-05-12: advisory