---
id: CVE-2025-40948
title: >-
  A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions <
  V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX
  RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions <
  V2.17.1), RUGGEDCO…
summary: >-
  A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions <
  V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX
  RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions <
  V2.17.1), RUGGEDCO…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-88
published: '2026-05-12'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40948'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-973901.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00397
epssPercentile: 0.33763
ingestedAt: '2026-06-29T14:29:18.070Z'
---

## Overview

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions < V2.17.1), RUGGEDCOM ROX RX1511 (All versions < V2.17.1), RUGGEDCOM ROX RX1512 (All versions < V2.17.1), RUGGEDCOM ROX RX1524 (All versions < V2.17.1), RUGGEDCOM ROX RX1536 (All versions < V2.17.1), RUGGEDCOM ROX RX5000 (All versions < V2.17.1). Affected devices do not properly validate input in the web server's JSON-RPC interface.

This could allow an authenticated remote attacker to read arbitrary files from the underlying operating system's filesystem with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
