Junglewise Threat Intelligence

CVE-2026-41918: Siemens RUGGEDCOM RST2428P sensitive information disclosure in browser cache

CVE-2026-41918 · Severity: medium · CVSS 5.7 · Published 2026-06-02

Technologies: Siemens RUGGEDCOM RST2428P. Vendors: Siemens.

Executive brief

Siemens RUGGEDCOM RST2428P is an industrial Ethernet switch used to manage network traffic in harsh environments like power plants or transportation hubs. A security flaw in the device's management interface causes sensitive configuration data to be stored in the web browser's cache. If an attacker gains access to a user's computer or browser session, they could retrieve this sensitive information, potentially compromising the security of the industrial network.

Technical details

A vulnerability (CWE-525) exists in the web-based management interface of Siemens RUGGEDCOM RST2428P switches running SINEC OS. The application fails to prevent the browser from caching sensitive information during configuration changes. An authenticated attacker with network access could exploit this by enticing a user to perform configuration tasks and then accessing the cached data through the user's browser. This requires user interaction and prior authentication. Siemens has addressed this issue in SINEC OS V4.0 and recommends that users update their firmware to the latest version.

Affected products

  • Siemens RUGGEDCOM RST2428P (6GK6242-6PA00) All versions < V4.0

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory
  • 2026-06-02: patched: Fixed in V4.0

References

Related threats