A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'traceroute' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.
The 'traceroute' tool available in the web interface of affected devices does not perform server-side input validation (no server-side input sanitization). An attacker with access to the web interface can inject malicious system commands as part of the input data passed to this tool. Due to the lack of server-side filtering (CWE-602 — client-side validation enforcement only), the injected commands are executed directly by the device's operating system with root privileges.
An authenticated remote attacker can execute arbitrary code with root privileges on the device, leading to complete device takeover, violation of data confidentiality and integrity, and system availability compromise.
All affected devices must be updated to firmware version V2.16.5 or later. Detailed patch information is available in the Siemens security bulletin SSA-301229 at: https://cert-portal.siemens.com/productcert/html/ssa-301229.html
RUGGEDCOM ROX MX5000, MX5000RE, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536 and RX5000 — all software versions below V2.16.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X