Command Injection Vulnerability in RUGGEDCOM ROX Products by Siemens
CVE-2025-32469
9.4CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-32469?
A vulnerability has been found in the web interface of various RUGGEDCOM ROX devices. The 'ping' tool lacks proper server-side input sanitation, enabling an authenticated remote attacker to exploit this flaw. By executing crafted input, the attacker could potentially run arbitrary commands with root privileges, posing significant security risks to affected systems.
Affected Version(s)
RUGGEDCOM ROX MX5000 0
RUGGEDCOM ROX MX5000RE 0
RUGGEDCOM ROX RX1400 0
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved