Siemens RUGGEDCOM ROX II Dynamic DNS Configuration Vulnerability Allowing Reverse Shell and Root Access

Vulnerability

A command injection vulnerability has been identified in the Siemens RUGGEDCOM ROX II family, affecting all versions prior to 2.17.0. During the Dynamic DNS configuration, it is possible to inject additional parameters, which under certain circumstances could be exploited to spawn a reverse shell and gain root access on the affected system.

Impact

Exploitation of this vulnerability could lead to unauthorized access with root privileges, allowing an attacker to execute commands as the root user and potentially manipulate the system at a fundamental level.

Remediation

Users are advised to update to version 2.17.0 or later. Additional information can be found on the Siemens Industry Support page.

Added: Dec 9, 2025, 9:02 PM
Updated: Dec 9, 2025, 9:02 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.5
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.