Siemens Ruggedcom ROX OS Command Injection Vulnerability (CVE-2025-40947)
CISA has republished a Siemens ProductCERT advisory disclosing a critical OS command injection vulnerability (CVE-2025-40947) in Siemens Ruggedcom ROX industrial networking devices. The flaw exists in the feature key installation process and allows an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Eleven product lines running versions prior to 2.17.1 are affected. These devices are widely deployed in critical infrastructure sectors including critical manufacturing, energy, and utilities worldwide. Siemens has released version 2.17.1 as the remediation.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. MEDIUM: Second-pass historical recalibration. This cyber advisory or vulnerability item is relevant to Cyber and technology-dependent Property/Casualty books, but it does not evidence confirmed insured loss, claims activity, ransomware/business interruption, critical infrastructure outage, or quantified market impact sufficient for HIGH.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Timeline
Lifecycle changed
monitoring → closed
Event Closed
auto_closed_monitoring_timeout
Status changed to monitoring
Auto-transitioned: no updates for 6 hours
active → monitoring
Status changed to active
evidence_trigger: authoritative_fast_track
signal → active
Impact changed
high → medium
Initial Detection
CISA has republished a Siemens ProductCERT advisory disclosing a critical OS command injection vulnerability (CVE-2025-40947) in Siemens Ruggedcom ROX industrial networking devices. The flaw exists in the feature key installation process and allows an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Eleven product lines running versions prior to 2.17.1 are affected. These devices are widely deployed in critical infrastructure sectors including critical manufacturing, energy, and utilities worldwide. Siemens has released version 2.17.1 as the remediation.
Affected devices do not properly sanitize user-supplied input during the feature key installation process. This could allow an authenticated remote attacker to inject arbitrary commands, resulting in remote code execution with root privileges on the underlying operating system.
Source: CISA Advisories (Official Advisory) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts