CVE Tools

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Unit 42By Emmanuel Zhou, Adam Robbie, Rick Wyble, Miguel Pereira13 min read

ResearchROX II

Our summary

Researchers from Palo Alto Networks' Unit 42 have uncovered a chain of three zero-day vulnerabilities in Siemens ROX II industrial switches, which could allow attackers to gain full root access and maintain persistent control over the devices. The flaws—CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949—range from arbitrary file disclosure to command injection and system persistence. Siemens has issued security advisories recommending an update to firmware version V2.17.1. These vulnerabilities underscore the need for strong input validation and secure coding practices in operational technology (OT) environments.

Read at Palo Alto Unit 42

Below is the opening; the full story is at Palo Alto Unit 42.

From Palo Alto Unit 42

Executive Summary

We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure.

This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949).…

Continue at Palo Alto Unit 42

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store