Command Injection Vulnerability in RUGGEDCOM ROX Products by Siemens
CVE-2025-32469

9.4CRITICAL

Key Information:

What is CVE-2025-32469?

A vulnerability has been found in the web interface of various RUGGEDCOM ROX devices. The 'ping' tool lacks proper server-side input sanitation, enabling an authenticated remote attacker to exploit this flaw. By executing crafted input, the attacker could potentially run arbitrary commands with root privileges, posing significant security risks to affected systems.

Affected Version(s)

RUGGEDCOM ROX MX5000 0

RUGGEDCOM ROX MX5000RE 0

RUGGEDCOM ROX RX1400 0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.