Input Validation Flaw in RUGGEDCOM Devices by Siemens
CVE-2025-40935

5.3MEDIUM

What is CVE-2025-40935?

An input validation issue exists in multiple Siemens RUGGEDCOM devices, impacting versions prior to V5.10.1. This vulnerability arises during the TLS certificate upload process within the web service, which does not adequately validate user input. A successful exploitation of this flaw may enable an authenticated remote attacker to trigger an unexpected device crash, resulting in a temporary denial of service (DoS). Organizations using these RUGGEDCOM devices should consider applying necessary updates and implementing security best practices to mitigate potential risks.

Affected Version(s)

RUGGEDCOM RMC8388 V5.X 0

RUGGEDCOM RS416Pv2 V5.X 0

RUGGEDCOM RS416v2 V5.X 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40935 : Input Validation Flaw in RUGGEDCOM Devices by Siemens