CVE-2025-40949Patch(siemens / ruggedcom_rox_mx5000)

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch siemens ruggedcom_rox_mx5000 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX1536 (All versions < V2.17.1), RUGGEDCOM ROX RX5000 (All versions < V2.17.1). Affected devices do not properly sanitize user-supplied input in the Scheduler functionality of the Web UI, allowing commands to be injected into the task scheduling backend. This could allow an authenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ruggedcom_rox_mx5000
  • ruggedcom_rox_mx5000_firmware
  • ruggedcom_rox_mx5000re
  • ruggedcom_rox_mx5000re_firmware

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-05-12); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
ruggedcom_rox_mx5000ruggedcom_rox_mx5000_firmwareruggedcom_rox_mx5000reruggedcom_rox_mx5000re_firmwareruggedcom_rox_rx1400ruggedcom_rox_rx1400_firmwareruggedcom_rox_rx1500ruggedcom_rox_rx1500_firmwareruggedcom_rox_rx1501ruggedcom_rox_rx1501_firmware

1 version affected across 22 products

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-05-12: 7Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-12: 7Technical Details · 2026-05-12: 605-1205-19
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-127
Disclosure1Patch6
2026-05-191
Disclosure1
Full discourse8 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/9MVY7SK942

    Post summary

    The tweet announces a critical vulnerability (CVE‑2025‑40949) in RuggedCOM devices, highlights the severity, and urges users to apply the available patch immediately.

    10010902
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/MkoBOcmF2H

    Post summary

    The tweet announces a critical vulnerability (CVE‑2025‑40949) in RuggedCom ROX devices with a 9.1 CVSS score and calls for an immediate patch.

    10000948
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/9F8iDQhbgG

    Post summary

    A critical vulnerability (CVE‑2025‑40949) affecting Ruggedcom ROX MX5000 devices has been disclosed, with a CVSS 9.1/10 score, and an immediate patch is available. No evidence of active exploitation or PoC is presented.

    10000914
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/utslDngFWA

    Post summary

    A critical vulnerability (CVE‑2025‑40949) affecting RuggedCOM ROX MX5000 series was announced, with a patch now available, but no proof of concept or exploitation details were provided.

    10000874
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/cfJPkwRD8P

    Post summary

    The post highlights a critical vulnerability (CVE‑2025‑40949) affecting Ruggedcom ROX MX5000 devices and urges users to apply the available patch.

    10000751
    34 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-40949 — CVSS 9.1/10 █████████░ A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &lt; V2.17.1), RUGGEDCOM ROX MX5000RE (All... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/TEjUUJoWZX

    Post summary

    The tweet announces a critical CVE-2025-40949 affecting Ruggedcom devices and informs readers that a patch is now available.

    10000744
    34 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-25787 ❗ CVE-2026-25786 ❗ CVE-2025-40949 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-6/ https://t.co/UF347jb2IS

    Post summary

    The post announces three new Siemens product CVEs, directing readers to external pages for more information, but it does not provide any proof‑of‑concept, exploit code, patch details, or technical vulnerability specifics.

    000001.2K
    6.7K followersView on X
  • Entity@0x2ed3bb60
    Disclosure

    🚨 CRITICAL: CVE-2025-40949 enables root command injection in Siemens RUGGEDCOM industrial routers via Web UI Scheduler. Authenticated attackers execute arbitrary OS commands. All versions &lt; V2.17.1 affected. Patch now. https://0x2ed3bb60.xyz/threat/fe5867dffa91090b

    Post summary

    The tweet announces CVE-2025-40949, detailing a root command injection flaw in Siemens RUGGEDCOM routers that can be exploited by authenticated users via the Web UI Scheduler, and notes an available patch for all affected versions.

    000008
    7 followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
HWsiemensruggedcom_rox_mx5000---
OSsiemensruggedcom_rox_mx5000_firmware---
HWsiemensruggedcom_rox_mx5000re---
OSsiemensruggedcom_rox_mx5000re_firmware---
HWsiemensruggedcom_rox_rx1400---
OSsiemensruggedcom_rox_rx1400_firmware---
HWsiemensruggedcom_rox_rx1500---
OSsiemensruggedcom_rox_rx1500_firmware---
HWsiemensruggedcom_rox_rx1501---
OSsiemensruggedcom_rox_rx1501_firmware---
HWsiemensruggedcom_rox_rx1510---
OSsiemensruggedcom_rox_rx1510_firmware---
HWsiemensruggedcom_rox_rx1511---
OSsiemensruggedcom_rox_rx1511_firmware---
HWsiemensruggedcom_rox_rx1512---
OSsiemensruggedcom_rox_rx1512_firmware---
HWsiemensruggedcom_rox_rx1524---
OSsiemensruggedcom_rox_rx1524_firmware---
HWsiemensruggedcom_rox_rx1536---
OSsiemensruggedcom_rox_rx1536_firmware---
HWsiemensruggedcom_rox_rx5000---
OSsiemensruggedcom_rox_rx5000_firmware---

Explore more