Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) — Threadlinqs Intelligence
As of 2026-07-17, Siemens Ruggedcom ROX II Three-Stage Zero-Day Exploit Chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1442 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
Unit 42 (Palo Alto Networks), working with Siemens ProductCERT, disclosed a chainable trio of zero-day vulnerabilities in Siemens RUGGEDCOM ROX II operational-technology switches: an
Siemens RUGGEDCOM ROX II is a ruggedized routing/switching operating system deployed on industrial switches and routers (MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, RX5000) used in electric utility substations, rail signaling networks, oil & gas SCADA backhaul, and other OT/ICS environments. Unit 42's OT Threat Research Lab researchers Emmanuel Zhou, Adam Robbie, Rick Wyble, and Mehmet Balta documented a three-stage exploit chain against firmware prior to V2.17.1, publishing findings jointly with Siemens ProductCERT (Miguel Pereira) on 2026-07-17, following coordinated-disclosure advisories issued by Siemens on 2026-05-12.
Stage 1 (CVE-2025-40948, CWE-88 Improper Neutralization of Argument Delimiters in a Command / Argument Injection, CVSS 3.1 6.8 MEDIUM / CVSS 4.0 6.1 MEDIUM): the ROX II web server's JSON-RPC interface fails to validate input passed to the xz compression utility, which a privileged configuration daemon invokes with root privileges. By supplying attacker-controlled arguments including the -f, -c, and -d flags, an authenticated remote attacker coerces xz into disclosing arbitrary filesystem contents — configuration files, credential hashes, and cryptographic key material — with root-level read access, entirely outside the intended compression workflow.
Stage 2 (CVE-2025-40947, CWE-78 OS Command Injection, CVSS 3.1 7.5 HIGH / CVSS 4.0 7.7 HIGH): the device's feature-key licensing mechanism verifies a cryptographic signature line by inserting the parsed signature string directly into a gpgv-invoking system command without sanitization during feature-key installation. An attacker first uploads a malicious script via the web management UI's file-upload functionality (e.g. a Python reverse-shell payload), then crafts a feature-key file whose signature field contains a command-substitution payload such as $(python /tmp/rev_shell.py). Installing this feature key executes the attacker's script with root privileges, yielding an immediate interactive root shell — an Abuse of Elevation Control Mechanisms via the trusted feature-key validation path.
Stage 3 (CVE-2025-40949, CWE-78 OS Command Injection, CVSS 3.1 9.1 CRITICAL / CVSS 4.0 8.9 HIGH): the web UI's task Scheduler function fails to sanitize user-supplied input before writing it into the task-scheduling backend (cron-equivalent) configuration. An authenticated attacker injects control characters and shell metacharacters into scheduled-task fields, causing arbitrary commands to execute as root on every subsequent scheduler tick. Because the payload lives in a persistent configuration file, this establishes root-level command execution that survives device reboots and firmware-level session resets — a durable OT implant primitive.
Chained together (Stage 1 credential/config harvesting via JSON-RPC argument injection -> Stage 2 root shell via feature-key/gpgv command injection -> Stage 3 persistent scheduler backdoor), the three flaws let any attacker who can authenticate to the ROX II web management interface (even with a low-privilege operator account, given CVE-2025-40947's PR:L requirement) pivot to complete, persistent root compromise of the OT switch — potentially enabling traffic interception, control-network pivoting, or destructive manipulation of substation/rail/pipeline communications. No in-the-wild exploitation or public attribution has been confirmed; this is a coordinated-disclosure PoC chain, not an observed intrusion. Siemens has patched all three flaws in firmware V2.17.1, available via the Siemens Industry Online Support portal, and Palo Alto Networks has published Advanced Threat Prevention signatures (97246, 97250, 97249) enabling virtual patching for customers unable to immediately upgrade firmware.
Weaknesses (CWE)
CWE-88, CWE-78
Target sectors: energy, electric utilities, rail transportation, oil and gas, manufacturing, critical infrastructure, industrial control systems
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-40948, CVE-2025-40947, CVE-2025-40949, T1078, T0859, T1059, T0871, T1053, T1505, T1068, T1053, T1548, T1211