Unauthorized Access Vulnerability in Siemens Products
CVE-2025-40805
10CRITICAL
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2025-40805?
A security vulnerability has been identified in specific Siemens devices that fail to properly enforce user authentication on certain API endpoints. This flaw could allow an attacker, who has identified the credentials of a legitimate user, to bypass authentication controls and impersonate that user, potentially leading to unauthorized actions within the system. Organizations using affected Siemens products should review their security postures and take appropriate actions to mitigate this risk.
Affected Version(s)
Industrial Edge Cloud Device (IECD) 0
Industrial Edge Device Kit - arm64 V1.10 0
Industrial Edge Device Kit - arm64 V1.11 0