File Upload Vulnerability in RUGGEDCOM ROX Products by Siemens
CVE-2025-33023
5.1MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2025-33023?
A vulnerability exists in various RUGGEDCOM ROX models where file upload restrictions are not enforced via the web interface. This permits authenticated remote attackers with elevated privileges to upload arbitrary files, which can lead to unauthorized access and exploitation of the affected device's capabilities. Organizations using these RUGGEDCOM products should assess their configurations and implement adequate security measures to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RUGGEDCOM ROX MX5000 0
RUGGEDCOM ROX MX5000RE 0
RUGGEDCOM ROX RX1400 0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved