Siemens Ruggedcom ROX Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in several Ruggedcom ROX products, all versions prior to V2.17.1. The issue arises from improper input validation during the feature key installation process, which could enable an authenticated remote attacker to inject arbitrary commands. This exploitation would result in remote code execution with root privileges on the underlying operating system.

Impact

Exploitation of this vulnerability allows for remote code execution with root privileges on the affected device's operating system.

Remediation

Siemens has released new versions for the affected products. Users are advised to update to the latest versions. For general security recommendations, Siemens suggests protecting network access to devices with appropriate measures and configuring the environment according to Siemens' operational guidelines for Industrial Security.

Added: May 12, 2026, 10:35 AM
Updated: May 12, 2026, 10:35 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.9
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.