Unit 42, the OT threat research lab of Palo Alto Networks, disclosed a chain of three zero-days in Siemens RUGGEDCOM ROX II industrial switches on July 17, 2026. The coordinated disclosure with Siemens produced three separate vendor advisories — an exceptional case in the OT sector, where fragmented responsibilities often slow remediation.
The vulnerabilities, documented as CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949, allow an authenticated attacker to progress from arbitrary file read to persistent root access. It is not known whether the chain was exploited in the wild prior to publication. The fix firmware is version V2.17.1.
- Unit 42 discovered three zero-days in Siemens ROX II OT switches in partnership with Siemens, with responsible disclosure and three vendor advisories (SSA-973901, SSA-078743, SSA-081142).
- CVE-2025-40948 (CVSS 6.8) enables arbitrary file disclosure via the xz utility running with root privileges.
- CVE-2025-40947 (CVSS 7.5) allows root-privileged command execution via command injection in feature key validation.
- CVE-2025-40949 (CVSS 9.1) provides persistence via OS command injection in the web task scheduler, surviving reboots.
- The official fix is firmware V2.17.1, applicable to 11 RUGGEDCOM ROX product families.
How the Chain Works: From xz to Root's Cron Table
The first link, CVE-2025-40948, exploits an insecure configuration of the xz utility that runs with root privileges. Unit 42 describes how an authenticated attacker can use the -f -c -d parameters — legitimate tool features — to read any file on the filesystem. The official vector string records a confidentiality-only impact (C:H), with changed scope (S:C) due to the network segmentation typical of OT environments.
The second stage, CVE-2025-40947, triggers in the feature key validation function. Missing input sanitization allows command injection executed with root privileges. The CVSS 7.5 reflects high attack complexity (AC:H) but, once overcome, the impact is total on integrity and availability.
The third link, CVE-2025-40949, is the critical one with CVSS 9.1. The web management task scheduler accepts unsanitized input that ends up in root's cron table. The result is persistence that survives reboots, turning the network device into a stable attack platform inside the OT segmentation.
The Official Numbers: Scoring and Affected Products
The CVE.org record for CVE-2025-40949 confirms the chain's highest severity: 9.1 in CVSS 3.1 (CRITICAL) and 8.9 in CVSS 4.0 (HIGH). The 3.1 vector string documents network access (AV:N), low complexity (AC:L), high privileges required (PR:H), no user interaction (UI:N), and changed scope (S:C) with total impact on confidentiality, integrity, and availability.
According to the same official record, the 11 affected product families include RUGGEDCOM ROX MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, and RX5000. All firmware versions prior to V2.17.1 are vulnerable. The Siemens advisories specify the same CWEs for the two active stages: CWE-78 (OS Command Injection) for CVE-2025-40947 and CVE-2025-40949, while CVE-2025-40948 falls under CWE-88 (Argument Injection or Modification).
"Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks." — Unit 42, Palo Alto Networks
Coordinated Disclosure: A Rare Model in OT
Researchers Emmanuel Zhou, Rick Wyble, Mehemt Balta, and Adam Robbie conducted the direct technical analysis on the firmware, while Siemens issued separate advisories for each vulnerability. This model — independent research on proprietary devices shared with the vendor before publication — remains exceptional in the OT sector.
Unit 42 states explicitly: "We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure." The documentation of a complete chain with scoring, CWEs, vectors, and a specific fix gives OT operators the elements for an informed risk assessment.
What to Do Now
Operators managing RUGGEDCOM ROX II devices must verify the installed firmware version. Updating to V2.17.1 is the only documented countermeasure in the Siemens advisories. Given the nature of these devices — segmentation components in energy, transportation, and healthcare networks — update planning requires the usual OT maintenance window.
It is not known whether the chain has been exploited in the wild. Operators unable to update immediately must assess risk based on their own network architecture and the criticality of the affected devices.
Analysis: The DeafNews Perspective
Network segmentation is often presented as a pillar of OT defense. Our editorial assessment is that this chain highlights a structural limit: when the boundary device itself is compromised, segmentation becomes a diagram rather than an actual barrier. This judgment is editorial, not a verified technical finding.
The exceptional nature of the coordinated disclosure — three separate advisories for a single chain — deserves attention. In the OT sector, where availability constraints often delay remediation for months, the joint publication by researchers and vendor offers a replicable model. Our assessment is that this approach increases pressure on other vendors to adopt similar practices.
Information has been verified against cited sources and is current as of publication.
Sources
- https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
- https://www.cve.org/CVERecord?id=CVE-2025-40949
- https://cert-portal.siemens.com/productcert/html/ssa-973901.html
- https://cert-portal.siemens.com/productcert/html/ssa-078743.html
- https://cert-portal.siemens.com/productcert/html/ssa-081142.html
- https://webboard-nsoc.ncsa.or.th/topic/3105/cyber-threat-intelligence-20-july-2026
- https://www.cisa.gov/news-events/ics-advisories/icsa-18-282-03
- https://support.industry.siemens.com/cs/us/en/view/109760683