CVE-2025-40591 Details
Description
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'Log Viewers' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute the 'tail' command with root privileges and disclose contents of all files in the filesystem.
A command injection vulnerability has been identified in the 'Log Viewers' tool of the RUGGEDCOM ROX II web interface, affecting several product models and all versions prior to V2.16.5. The vulnerability arises from inadequate server-side input validation, allowing authenticated remote attackers to execute the 'tail' command with root privileges. This exploitation could lead to unauthorized access to the contents of all files within the filesystem.
Users are advised to update to version V2.16.5 or later. For more information, visit the Siemens Industry Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-301229.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens RUGGEDCOM ROX MX5000 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX MX5000RE | All versions |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1400 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1500 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1501 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1510 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1511 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1512 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1524 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX1536 | < V2.16.5 |
CPE
Remediation
| |
| Siemens RUGGEDCOM ROX RX5000 | < V2.16.5 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2025 | New CVE Received | [email protected] |
Volerion