CRITICAL🇵🇱 Wersja polska

CVE-2025-33024

CVSS 9.4v4.0pub. 2025-05-13upd. 2026-04-15

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'tcpdump' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

🤖 AI Analysis
How it works

The 'tcpdump' tool available through the web interface of RUGGEDCOM ROX devices does not perform sufficient input validation on the server side. An authenticated remote attacker can provide specially crafted input data that will be interpreted as system commands. As a result, it is possible to execute arbitrary commands with the highest system privileges (root). The vulnerability is classified as CWE-602, which means validation logic is only performed on the client side, bypassing server-side verification.

Impact

An authenticated remote attacker can execute arbitrary code with root privileges, which in practice means complete takeover of the device, ability to modify configuration, disrupt industrial network operations, and lateral movement in the OT/IT environment.

Mitigation & patch

Update the firmware to version V2.16.5 or later. Detailed information and patches are available in the Siemens security bulletin at: https://cert-portal.siemens.com/productcert/html/ssa-301229.html

Who is affected

RUGGEDCOM ROX MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, and RX5000 — all software versions below V2.16.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References