Input Validation Flaw in SIMATIC RTLS Locating Manager by Siemens
CVE-2025-40746

9.4CRITICAL

Key Information:

Vendor

Siemens

Vendor
CVE Published:
12 August 2025

What is CVE-2025-40746?

A serious input validation flaw exists in the SIMATIC RTLS Locating Manager, impacting all versions prior to V3.2. This vulnerability allows an authenticated remote attacker with high privileges to exploit the backup script, potentially executing arbitrary code with 'NT Authority/SYSTEM' privileges. Effective mitigation measures should be taken to protect against unauthorized access and to ensure system integrity.

Affected Version(s)

SIMATIC RTLS Locating Manager 0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40746 : Input Validation Flaw in SIMATIC RTLS Locating Manager by Siemens