Junglewise Threat Intelligence

CVE-2025-40949: Siemens RUGGEDCOM ROX command injection in Scheduler Web UI

CVE-2025-40949 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: Siemens RUGGEDCOM ROX RX1500, Siemens RUGGEDCOM ROX MX5000RE, Siemens RUGGEDCOM ROX RX1536, Siemens RUGGEDCOM ROX RX5000, Siemens RUGGEDCOM ROX RX1510, Siemens RUGGEDCOM ROX RX1400, Siemens RUGGEDCOM ROX RX1511, Siemens RUGGEDCOM ROX RX1524, Siemens RUGGEDCOM ROX MX5000, Siemens RUGGEDCOM ROX RX1501, Siemens RUGGEDCOM ROX RX1512. Vendors: Siemens.

Executive brief

Siemens RUGGEDCOM ROX devices, which are industrial Ethernet switches used in harsh environments like power substations and traffic control, contain a security flaw in their task scheduling interface. An authorized user could exploit this flaw to take full control of the device's underlying operating system. This could lead to a complete loss of device availability, unauthorized changes to network traffic, or a foothold for further attacks within critical infrastructure environments.

Technical details

A vulnerability classified as OS Command Injection (CWE-78) exists in the Scheduler functionality of the Web UI in Siemens RUGGEDCOM ROX II devices. The issue stems from improper sanitization of user-supplied input, which allows commands to be injected into the task scheduling backend. An authenticated remote attacker with high privileges can exploit this to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability affects multiple RUGGEDCOM ROX models (MX5000, RX1400, RX1500 series, etc.) running firmware versions prior to V2.17.1. Siemens has released firmware V2.17.1 to address this issue.

Affected products

  • Siemens RUGGEDCOM ROX MX5000 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX MX5000RE firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1400 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1500 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1501 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1510 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1511 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1512 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1524 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX1536 firmware < V2.17.1
  • Siemens RUGGEDCOM ROX RX5000 firmware < V2.17.1

Timeline

  • 2026-05-12: advisory: Initial publication by Siemens ProductCERT
  • 2026-05-12: patched: Firmware V2.17.1 released to address the vulnerability

References

Related threats