Threat reportVulnerabilityTL-2026-1442
Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949)
Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (TL-2026-1442), also tracked as Three Steps to the Terminal, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-07-17. It has no confirmed attribution, affects Siemens RUGGEDCOM ROX II, references 3 CVEs (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949), maps to 16 MITRE ATT&CK techniques (T0813, T0859, T0871), and is covered by 9 detection rules and 22 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1442
- Threat ID
- TL-2026-1442
- Also known as
- Three Steps to the Terminal, ROX II Zero-Day Trilogy
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- energy, electric utilities, rail transportation, oil and gas, manufacturing, critical infrastructure, industrial control systems
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
Malware and tooling: Palo Alto Networks Advanced Threat Prevention signature 97246, Palo Alto Networks Advanced Threat Prevention signature 97249, Palo Alto Networks Advanced Threat Prevention signature 97250
How Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain works
Unit 42 (Palo Alto Networks), working with Siemens ProductCERT, disclosed a chainable trio of zero-day vulnerabilities in Siemens RUGGEDCOM ROX II operational-technology switches: an unauthenticated-adjacent arbitrary file disclosure via xz utility abuse (CVE-2025-40948), a command injection in feature-key signature validation via gpgv (CVE-2025-40947), and a persistent root code execution flaw in the web UI task scheduler (CVE-2025-40949). Chained end-to-end, an authenticated attacker escalates from a low-privileged session to full, reboot-surviving root control of critical OT network infrastructure.
Siemens RUGGEDCOM ROX II is a ruggedized routing/switching operating system deployed on industrial switches and routers (MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, RX5000) used in electric utility substations, rail signaling networks, oil & gas SCADA backhaul, and other OT/ICS environments. Unit 42's OT Threat Research Lab researchers Emmanuel Zhou, Adam Robbie, Rick Wyble, and Mehmet Balta documented a three-stage exploit chain against firmware prior to V2.17.1, publishing findings jointly with Siemens ProductCERT (Miguel Pereira) on 2026-07-17, following coordinated-disclosure advisories issued by Siemens on 2026-05-12.
Stage 1 (CVE-2025-40948, CWE-88 Improper Neutralization of Argument Delimiters in a Command / Argument Injection, CVSS 3.1 6.8 MEDIUM / CVSS 4.0 6.1 MEDIUM): the ROX II web server's JSON-RPC interface fails to validate input passed to the xz compression utility, which a privileged configuration daemon invokes with root privileges. By supplying attacker-controlled arguments including the -f, -c, and -d flags, an authenticated remote attacker coerces xz into disclosing arbitrary filesystem contents — configuration files, credential hashes, and cryptographic key material — with root-level read access, entirely outside the intended compression workflow.
Stage 2 (CVE-2025-40947, CWE-78 OS Command Injection, CVSS 3.1 7.5 HIGH / CVSS 4.0 7.7 HIGH): the device's feature-key licensing mechanism verifies a cryptographic signature line by inserting the parsed signature string directly into a gpgv-invoking system command without sanitization during feature-key installation. An attacker first uploads a malicious script via the web management UI's file-upload functionality (e.g. a Python reverse-shell payload), then crafts a feature-key file whose signature field contains a command-substitution payload such as $(python /tmp/rev_shell.py). Installing this feature key executes the attacker's script with root privileges, yielding an immediate interactive root shell — an Abuse of Elevation Control Mechanisms via the trusted feature-key validation path.
Stage 3 (CVE-2025-40949, CWE-78 OS Command Injection, CVSS 3.1 9.1 CRITICAL / CVSS 4.0 8.9 HIGH): the web UI's task Scheduler function fails to sanitize user-supplied input before writing it into the task-scheduling backend (cron-equivalent) configuration. An authenticated attacker injects control characters and shell metacharacters into scheduled-task fields, causing arbitrary commands to execute as root on every subsequent scheduler tick. Because the payload lives in a persistent configuration file, this establishes root-level command execution that survives device reboots and firmware-level session resets — a durable OT implant primitive.
Chained together (Stage 1 credential/config harvesting via JSON-RPC argument injection -> Stage 2 root shell via feature-key/gpgv command injection -> Stage 3 persistent scheduler backdoor), the three flaws let any attacker who can authenticate to the ROX II web management interface (even with a low-privilege operator account, given CVE-2025-40947's PR:L requirement) pivot to complete, persistent root compromise of the OT switch — potentially enabling traffic interception, control-network pivoting, or destructive manipulation of substation/rail/pipeline communications. No in-the-wild exploitation or public attribution has been confirmed; this is a coordinated-disclosure PoC chain, not an observed intrusion. Siemens has patched all three flaws in firmware V2.17.1, available via the Siemens Industry Online Support portal, and Palo Alto Networks has published Advanced Threat Prevention signatures (97246, 97250, 97249) enabling virtual patching for customers unable to immediately upgrade firmware.
MITRE ATT&CK techniques used in TL-2026-1442
Impact
persistence
T0859 Valid Accounts; T1693.001 System Firmware
Execution
T0871 Execution through API; T1059 Command and Scripting Interpreter
Collection
Persistence
T1053 Scheduled Task/Job; T1505 Server Software Component
Privilege Escalation
T1053 Scheduled Task/Job; T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Initial Access
Discovery
T1083 File and Directory Discovery
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Credentials In Files
Affected products and versions in Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
- Siemens — RUGGEDCOM ROX II
Vulnerable versions: All versions prior to V2.17.1
Fixed in: V2.17.1 and later - Siemens — RUGGEDCOM MX5000
Vulnerable versions: < V2.17.1
Fixed in: V2.17.1 - Siemens — RUGGEDCOM MX5000RE
Vulnerable versions: < V2.17.1
Fixed in: V2.17.1 - Siemens — RUGGEDCOM RX1400
Vulnerable versions: < V2.17.1
Fixed in: V2.17.1 - Siemens — RUGGEDCOM RX1500 series (RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536)
Vulnerable versions: < V2.17.1
Fixed in: V2.17.1 - Siemens — RUGGEDCOM RX5000
Vulnerable versions: < V2.17.1
Fixed in: V2.17.1
Remediation for Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
Patches
- Siemens RUGGEDCOM ROX firmware V2.17.1 (fixes CVE-2025-40948, CVE-2025-40947, CVE-2025-40949)
Immediate actions
- Upgrade all Siemens RUGGEDCOM ROX II devices to firmware V2.17.1 or later via https://support.industry.siemens.com/cs/ww/en/view/110002017/
- Restrict web management interface access to trusted management networks/VLANs only
- Disable or tightly ACL the JSON-RPC interface where not operationally required
- Audit existing task scheduler entries for unauthorized or unrecognized scheduled commands
- Review recent feature-key installation events for anomalous signature payloads or gpgv invocation anomalies
- Rotate credentials and cryptographic keys on any device suspected of file-disclosure exposure via CVE-2025-40948
Workarounds
- Restrict network access to the ROX II web management interface and JSON-RPC endpoint to dedicated management VLANs behind firewall ACLs
- Disable feature-key installation functionality via web UI where not actively needed
- Apply Palo Alto Networks NGFW virtual patching (signature IDs 97246, 97250, 97249) as interim mitigation
Longer-term hardening
- Segment OT switch management planes from general IT/OT data networks per IEC 62443 zone/conduit guidance
- Deploy virtual patching / IPS signatures (Palo Alto Advanced Threat Prevention IDs 97246, 97250, 97249) where immediate firmware upgrade is not feasible
- Enforce least-privilege operator accounts on ROX II web UI to reduce blast radius of PR:L-gated exploitation
- Implement configuration-integrity monitoring on scheduler/cron backend files
- Establish a firmware patch-management cadence for all RUGGEDCOM ROX fleet devices
CVEs associated with Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
CVE-2025-40948, CVE-2025-40947, CVE-2025-40949
Weaknesses (CWE) in Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
Timeline of Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
- Siemens releases RUGGEDCOM ROX firmware V2.17.1 via the Siemens Industry Online Support portal, fixing all three chained vulnerabilities.
- CISA publishes ICS advisory ICSA-26-134-12 covering all three RUGGEDCOM ROX vulnerabilities for critical-infrastructure asset owners.
- Siemens ProductCERT publishes SSA-081142, disclosing CVE-2025-40949 (task scheduler command injection, CVSS 3.1 9.1 CRITICAL) with fix in firmware V2.17.1.
- Siemens ProductCERT publishes SSA-078743, disclosing CVE-2025-40947 (feature-key/gpgv command injection, CVSS 3.1 7.5) with fix in firmware V2.17.1.
- Siemens ProductCERT publishes SSA-973901, disclosing CVE-2025-40948 (arbitrary file disclosure via xz argument injection, CVSS 3.1 6.8) with fix in firmware V2.17.1.
- Threadlinqs Intelligence Platform ingests the Unit 42 disclosure via HUNT phase for threat-skeleton creation as TL-2026-1442.
- Palo Alto Networks publishes Advanced Threat Prevention detection signatures (IDs 97246, 97250, 97249) for the exploit chain, alongside NGFW virtual-patching guidance for OT Device Security customers.
- Unit 42 (Palo Alto Networks) OT Threat Research Lab researchers Emmanuel Zhou, Adam Robbie, Rick Wyble, and Mehmet Balta publish 'Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy,' detailing the full three-stage exploit chain in coordination with Siemens ProductCERT (Miguel Pereira).
Sources cited for Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
- SSA-973901: Siemens ProductCERT Advisory (CVE-2025-40948)
- SSA-078743: Siemens ProductCERT Advisory (CVE-2025-40947)
- SSA-081142: Siemens ProductCERT Advisory (CVE-2025-40949)
- ICSA-26-134-12: Siemens RUGGEDCOM ROX
- NVD CVE-2025-40949 Detail
- NVD CVE-2025-40947 Detail
- NVD CVE-2025-40948 Detail
- Siemens Industry Online Support - RUGGEDCOM ROX firmware download
Detection coverage for TL-2026-1442
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1442 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.