Command Injection Vulnerability in RUGGEDCOM ROX Products by Siemens
CVE-2025-33025

9.4CRITICAL

Key Information:

What is CVE-2025-33025?

A command injection vulnerability has been discovered in the 'traceroute' tool of the web interface for various Siemens RUGGEDCOM ROX devices. This weakness stems from inadequate server-side input sanitation. An authenticated remote attacker could exploit this flaw to execute arbitrary commands with root privileges, potentially compromising the security and integrity of affected systems. It is recommended that users of all impacted devices upgrade to version V2.16.5 or later to mitigate this risk.

Affected Version(s)

RUGGEDCOM ROX MX5000 0

RUGGEDCOM ROX MX5000RE 0

RUGGEDCOM ROX RX1400 0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.