---
id: CVE-2025-40935
title: >-
  A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions <
  V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2
  V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions <
  V5.10.1…
summary: >-
  A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions <
  V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2
  V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions <
  V5.10.1…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-20
published: '2025-12-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40935'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-763474.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00248
epssPercentile: 0.14519
ingestedAt: '2026-09-30T20:23:19.436Z'
---

## Overview

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100P (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2288 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300P V5.X (All versions < V5.10.1), RUGGEDCOM RSG2488 V5.X (All versions < V5.10.1), RUGGEDCOM RSG907R (All versions < V5.10.1), RUGGEDCOM RSG908C (All versions < V5.10.1), RUGGEDCOM RSG909R (All versions < V5.10.1), RUGGEDCOM RSG910C (All versions < V5.10.1), RUGGEDCOM RSG920P V5.X (All versions < V5.10.1), RUGGEDCOM RSL910 (All versions < V5.10.1), RUGGEDCOM RST2228 (All versions < V5.10.1), RUGGEDCOM RST2228P (All versions < V5.10.1), RUGGEDCOM RST916C (All versions < V5.10.1), RUGGEDCOM RST916P (All versions < V5.10.1). Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
