Siemens RUGGEDCOM ROX II Command Injection Vulnerability in Traceroute Tool Allowing Privileged Code Execution

Vulnerability

A command injection vulnerability has been identified in the web interface of several RUGGEDCOM ROX II devices, all versions prior to 2.16.5. The vulnerability arises from inadequate server-side input validation in the 'traceroute' tool, allowing authenticated remote attackers to execute arbitrary code with root privileges on the affected devices.

Impact

Exploitation of this vulnerability could lead to authenticated remote attackers executing arbitrary code with root privileges on the affected devices.

Remediation

Users are advised to update to version 2.16.5 or later. For more information, visit the Siemens Industry Support page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.