CVE 6.8 MEDIUM

CVE-2025-40948_CVE-2025-40948

6.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Description

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX1536 (All versions < V2.17.1), RUGGEDCOM ROX RX5000 (All versions < V2.17.1). Affected devices do not properly validate input in the web server's JSON-RPC interface.

This could allow an authenticated remote attacker to read arbitrary files from the underlying operating system's filesystem with root privileges.

Basic Information

ID CVE-2025-40948
Source siemens
Published May 12, 2026 at 08:20

Affected Product

Vendor Siemens
Product RUGGEDCOM ROX MX5000
Affected Versions Siemens RUGGEDCOM ROX MX5000 0
Siemens RUGGEDCOM ROX MX5000RE 0
Siemens RUGGEDCOM ROX RX1400 0
Siemens RUGGEDCOM ROX RX1500 0
Siemens RUGGEDCOM ROX RX1501 0
Siemens RUGGEDCOM ROX RX1510 0
Siemens RUGGEDCOM ROX RX1511 0
Siemens RUGGEDCOM ROX RX1512 0
Siemens RUGGEDCOM ROX RX1524 0
Siemens RUGGEDCOM ROX RX1536 0
Siemens RUGGEDCOM ROX RX5000 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.