
CVE-2025-40948/40947/40949: Siemens ROX II — Root Access via Zero-Day Chain (June 2025)
CVE-2025-40948/40947/40949 — Siemens ROX II OT Switches
A chained exploit involving CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949 allows attackers to gain persistent root access on Siemens ROX II operational technology (OT) switches. These vulnerabilities are rated critical and have no public patch as of June 2025. Exploitation has been demonstrated and could lead to full device takeover in industrial environments.
Attack Vector
Attackers exploit the chain by first leveraging arbitrary file disclosure to gather sensitive configuration or credential data. Next, command injection enables privilege escalation, granting root access. The final stage allows persistent code execution, enabling attackers to maintain control over compromised switches. No user interaction is required; access to management interfaces or network adjacency is sufficient. The attack can be performed remotely if the device is exposed to untrusted networks.
Who Is at Risk
All Siemens ROX II OT switches are affected, regardless of deployment region or sector. These devices are widely used in industrial control networks, including energy, manufacturing, and critical infrastructure. Organizations with internet-exposed or remotely managed ROX II switches are at highest risk. Siemens is the primary affected vendor; no evidence of compromise in other product lines has been reported.
Patch & Mitigate
- Patch: No official patch is available as of June 2025. Monitor Siemens advisories for updates and apply fixes immediately when released.
- Workaround: Isolate ROX II switches from untrusted networks. Restrict management interface access to trusted hosts. Apply strict network segmentation and firewall rules.
- Detect: Monitor for unusual authentication attempts, unexpected configuration changes, and anomalous commands in switch logs. Watch for outbound connections from switches to unknown destinations.
MITRE ATT&CK
- TA0004 — Privilege Escalation: Attackers use command injection to gain root privileges on the device.
- TA0005 — Defense Evasion: Persistent code execution enables attackers to evade detection and maintain long-term access.
- TA0007 — Discovery: File disclosure vulnerability allows attackers to enumerate sensitive files and configurations.
Source: https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

