CRITICAL🇵🇱 Wersja polska

CVE-2025-33025

CVSS 9.4v4.0pub. 2025-05-13upd. 2026-04-15

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'traceroute' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

🤖 AI Analysis
How it works

The 'traceroute' tool available in the web interface of affected devices does not perform server-side input validation (no server-side input sanitization). An attacker with access to the web interface can inject malicious system commands as part of the input data passed to this tool. Due to the lack of server-side filtering (CWE-602 — client-side validation enforcement only), the injected commands are executed directly by the device's operating system with root privileges.

Impact

An authenticated remote attacker can execute arbitrary code with root privileges on the device, leading to complete device takeover, violation of data confidentiality and integrity, and system availability compromise.

Mitigation & patch

All affected devices must be updated to firmware version V2.16.5 or later. Detailed patch information is available in the Siemens security bulletin SSA-301229 at: https://cert-portal.siemens.com/productcert/html/ssa-301229.html

Who is affected

RUGGEDCOM ROX MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536 and RX5000 — all software versions below V2.16.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References