{"schema_version":1,"title":"Siemens RUGGEDCOM RST2428P vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Siemens RUGGEDCOM RST2428P: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-41918, was published on 2 June 2026.","url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p","json_url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ruggedcom-rst2428p","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":16,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":8},"latest":[{"cve":"CVE-2026-41918","cvss":5.7,"slug":"cve-2026-41918-siemens-ruggedcom-rst2428p-sensitive-information-disclosure-in","title":"Siemens RUGGEDCOM RST2428P sensitive information disclosure in browser cache","severity":"medium","exploited":false,"published_at":"2026-06-02T14:16:53.2+00:00","url":"https://junglewise.ai/threats/cve-2026-41918-siemens-ruggedcom-rst2428p-sensitive-information-disclosure-in"},{"cve":"CVE-2026-3784","cvss":6.5,"epss":0.0002,"slug":"cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials","title":"curl wrong proxy connection reuse with credentials","severity":"medium","exploited":false,"published_at":"2026-03-11T11:16:00.437+00:00","url":"https://junglewise.ai/threats/cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials"},{"cve":"CVE-2026-26158","cvss":7,"epss":0.0001,"slug":"cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link","title":"BusyBox arbitrary file modification via unvalidated tar link entries","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.607+00:00","url":"https://junglewise.ai/threats/cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link"},{"cve":"CVE-2026-26157","cvss":7,"epss":0.0014,"slug":"cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities","title":"BusyBox path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.4+00:00","url":"https://junglewise.ai/threats/cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2026-25210","cvss":6.9,"epss":0.0001,"slug":"cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation","title":"libexpat integer overflow in doContent tag buffer reallocation","severity":"medium","exploited":false,"published_at":"2026-01-30T07:16:15.57+00:00","url":"https://junglewise.ai/threats/cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation"},{"cve":"CVE-2026-1489","cvss":5.4,"epss":0.0002,"slug":"cve-2026-1489-gnome-glib-integer-overflow-in-unicode-case-conversion","title":"GNOME GLib integer overflow in Unicode case conversion","severity":"medium","exploited":false,"published_at":"2026-01-27T15:15:57.37+00:00","url":"https://junglewise.ai/threats/cve-2026-1489-gnome-glib-integer-overflow-in-unicode-case-conversion"},{"cve":"CVE-2026-1484","cvss":4.2,"epss":0.0002,"slug":"cve-2026-1484-gnome-glib-integer-overflow-in-base64-encoding","title":"GNOME GLib integer overflow in Base64 encoding","severity":"medium","exploited":false,"published_at":"2026-01-27T14:15:56.05+00:00","url":"https://junglewise.ai/threats/cve-2026-1484-gnome-glib-integer-overflow-in-base64-encoding"},{"cve":"CVE-2026-24515","cvss":2.9,"epss":0.0001,"slug":"cve-2026-24515-libexpat-null-pointer-dereference-in-xml","title":"libexpat NULL pointer dereference in XML_ExternalEntityParserCreate","severity":"low","exploited":false,"published_at":"2026-01-23T08:16:01.49+00:00","url":"https://junglewise.ai/threats/cve-2026-24515-libexpat-null-pointer-dereference-in-xml"},{"cve":"CVE-2025-39864","cvss":8.8,"epss":0.0015,"slug":"cve-2025-39864-linux-kernel-use-after-free-in-cfg80211-wi-fi-bss-update","title":"Linux Kernel use-after-free in cfg80211 Wi-Fi BSS update","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:45.42+00:00","url":"https://junglewise.ai/threats/cve-2025-39864-linux-kernel-use-after-free-in-cfg80211-wi-fi-bss-update"},{"cve":"CVE-2025-39860","cvss":8,"epss":0.0015,"slug":"cve-2025-39860-linux-kernel-use-after-free-in-bluetooth-l2cap-sock-cleanup","title":"Linux Kernel use-after-free in Bluetooth l2cap_sock_cleanup_listen","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:44.973+00:00","url":"https://junglewise.ai/threats/cve-2025-39860-linux-kernel-use-after-free-in-bluetooth-l2cap-sock-cleanup"},{"cve":"CVE-2025-39841","cvss":9.8,"epss":0.0017,"slug":"cve-2025-39841-linux-kernel-lpfc-use-after-free-in-deferred-receive-path","title":"Linux Kernel lpfc use-after-free in deferred receive path","severity":"critical","exploited":false,"published_at":"2025-09-19T16:15:42.813+00:00","url":"https://junglewise.ai/threats/cve-2025-39841-linux-kernel-lpfc-use-after-free-in-deferred-receive-path"},{"cve":"CVE-2025-39839","cvss":8.8,"epss":0.0016,"slug":"cve-2025-39839-linux-kernel-batman-adv-oob-read-write-in-network-coding-decode","title":"Linux Kernel batman-adv OOB read/write in network-coding decode","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:42.57+00:00","url":"https://junglewise.ai/threats/cve-2025-39839-linux-kernel-batman-adv-oob-read-write-in-network-coding-decode"},{"cve":"CVE-2025-7039","cvss":3.7,"epss":0.0008,"slug":"cve-2025-7039-glib-integer-overflow-in-temporary-file-creation","title":"GLib integer overflow in temporary file creation","severity":"low","exploited":false,"published_at":"2025-09-03T02:15:38.12+00:00","url":"https://junglewise.ai/threats/cve-2025-7039-glib-integer-overflow-in-temporary-file-creation"},{"cve":"CVE-2025-8732","cvss":3.3,"epss":0.0003,"slug":"cve-2025-8732-gnome-libxml2-uncontrolled-recursion-in-xmlparsesgmlcatalog","title":"GNOME libxml2 uncontrolled recursion in xmlParseSGMLCatalog","severity":"low","exploited":false,"published_at":"2025-08-08T17:15:30.583+00:00","url":"https://junglewise.ai/threats/cve-2025-8732-gnome-libxml2-uncontrolled-recursion-in-xmlparsesgmlcatalog"},{"cve":"CVE-2025-6052","cvss":3.7,"epss":0.0028,"slug":"cve-2025-6052-gnome-glib-integer-overflow-in-g-string-maybe-expand","title":"GNOME GLib integer overflow in g_string_maybe_expand","severity":"low","exploited":false,"published_at":"2025-06-13T16:15:28.23+00:00","url":"https://junglewise.ai/threats/cve-2025-6052-gnome-glib-integer-overflow-in-g-string-maybe-expand"},{"cve":"CVE-2024-41996","cvss":7.5,"slug":"cve-2024-41996-openssl-and-siemens-dhe-resource-exhaustion-in-public-key","title":"OpenSSL and Siemens DHE resource exhaustion in public key validation","severity":"high","exploited":false,"published_at":"2024-08-26T06:15:04.603+00:00","url":"https://junglewise.ai/threats/cve-2024-41996-openssl-and-siemens-dhe-resource-exhaustion-in-public-key"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Siemens RUGGEDCOM APE1808","slug":"ruggedcom-ape1808","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/ruggedcom-ape1808"},{"name":"Siemens ROX II","slug":"rox-ii","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rox-ii"},{"name":"Siemens SINEC OS","slug":"sinec-os","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/sinec-os"},{"name":"Siemens Solid Edge","slug":"solid-edge","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/solid-edge"},{"name":"Siemens SIMATIC S7-1500 TM MFP GNU/Linux subsystem","slug":"simatic-s7-1500-tm-mfp-gnu-linux-subsystem","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-tm-mfp-gnu-linux-subsystem"},{"name":"Siemens Ruggedcom Rox II","slug":"ruggedcom-rox-ii","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/ruggedcom-rox-ii"},{"name":"Siemens Reyrolle 7SR5","slug":"reyrolle-7sr5","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/reyrolle-7sr5"},{"name":"Siemens Simcenter Femap","slug":"simcenter-femap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/simcenter-femap"}],"technology":{"hub":true,"name":"Siemens RUGGEDCOM RST2428P","slug":"ruggedcom-rst2428p","vendor":{"name":"Siemens","slug":"siemens","url":"https://junglewise.ai/threats/vendors/siemens"},"aliases":[],"category":"firmware","homepage":"https://www.siemens.com/ruggedcom","description":"Firmware for the RUGGEDCOM RST2428P, a 28-port rack-mounted managed Ethernet switch designed for harsh environments.","url":"https://junglewise.ai/threats/technologies/ruggedcom-rst2428p"},"most_severe":[{"cve":"CVE-2025-39841","cvss":9.8,"epss":0.0017,"slug":"cve-2025-39841-linux-kernel-lpfc-use-after-free-in-deferred-receive-path","title":"Linux Kernel lpfc use-after-free in deferred receive path","severity":"critical","exploited":false,"published_at":"2025-09-19T16:15:42.813+00:00","url":"https://junglewise.ai/threats/cve-2025-39841-linux-kernel-lpfc-use-after-free-in-deferred-receive-path"},{"cve":"CVE-2025-39839","cvss":8.8,"epss":0.0016,"slug":"cve-2025-39839-linux-kernel-batman-adv-oob-read-write-in-network-coding-decode","title":"Linux Kernel batman-adv OOB read/write in network-coding decode","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:42.57+00:00","url":"https://junglewise.ai/threats/cve-2025-39839-linux-kernel-batman-adv-oob-read-write-in-network-coding-decode"},{"cve":"CVE-2025-39864","cvss":8.8,"epss":0.0015,"slug":"cve-2025-39864-linux-kernel-use-after-free-in-cfg80211-wi-fi-bss-update","title":"Linux Kernel use-after-free in cfg80211 Wi-Fi BSS update","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:45.42+00:00","url":"https://junglewise.ai/threats/cve-2025-39864-linux-kernel-use-after-free-in-cfg80211-wi-fi-bss-update"},{"cve":"CVE-2025-39860","cvss":8,"epss":0.0015,"slug":"cve-2025-39860-linux-kernel-use-after-free-in-bluetooth-l2cap-sock-cleanup","title":"Linux Kernel use-after-free in Bluetooth l2cap_sock_cleanup_listen","severity":"high","exploited":false,"published_at":"2025-09-19T16:15:44.973+00:00","url":"https://junglewise.ai/threats/cve-2025-39860-linux-kernel-use-after-free-in-bluetooth-l2cap-sock-cleanup"},{"cve":"CVE-2024-41996","cvss":7.5,"slug":"cve-2024-41996-openssl-and-siemens-dhe-resource-exhaustion-in-public-key","title":"OpenSSL and Siemens DHE resource exhaustion in public key validation","severity":"high","exploited":false,"published_at":"2024-08-26T06:15:04.603+00:00","url":"https://junglewise.ai/threats/cve-2024-41996-openssl-and-siemens-dhe-resource-exhaustion-in-public-key"},{"cve":"CVE-2026-26157","cvss":7,"epss":0.0014,"slug":"cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities","title":"BusyBox path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.4+00:00","url":"https://junglewise.ai/threats/cve-2026-26157-busybox-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2026-26158","cvss":7,"epss":0.0001,"slug":"cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link","title":"BusyBox arbitrary file modification via unvalidated tar link entries","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:21.607+00:00","url":"https://junglewise.ai/threats/cve-2026-26158-busybox-arbitrary-file-modification-via-unvalidated-tar-link"},{"cve":"CVE-2026-25210","cvss":6.9,"epss":0.0001,"slug":"cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation","title":"libexpat integer overflow in doContent tag buffer reallocation","severity":"medium","exploited":false,"published_at":"2026-01-30T07:16:15.57+00:00","url":"https://junglewise.ai/threats/cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation"},{"cve":"CVE-2026-3784","cvss":6.5,"epss":0.0002,"slug":"cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials","title":"curl wrong proxy connection reuse with credentials","severity":"medium","exploited":false,"published_at":"2026-03-11T11:16:00.437+00:00","url":"https://junglewise.ai/threats/cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials"},{"cve":"CVE-2026-41918","cvss":5.7,"slug":"cve-2026-41918-siemens-ruggedcom-rst2428p-sensitive-information-disclosure-in","title":"Siemens RUGGEDCOM RST2428P sensitive information disclosure in browser cache","severity":"medium","exploited":false,"published_at":"2026-06-02T14:16:53.2+00:00","url":"https://junglewise.ai/threats/cve-2026-41918-siemens-ruggedcom-rst2428p-sensitive-information-disclosure-in"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}