PT-2025-20861 · Siemens+1 · Ruggedcom Rox Rx1500+9

Published

2025-05-13

·

Updated

2025-05-13

·

CVE-2025-33024

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: RUGGEDCOM ROX MX5000 versions prior to V2.16.5 RUGGEDCOM ROX MX5000RE versions prior to V2.16.5 RUGGEDCOM ROX RX1400 versions prior to V2.16.5 RUGGEDCOM ROX RX1500 versions prior to V2.16.5 RUGGEDCOM ROX RX1501 versions prior to V2.16.5 RUGGEDCOM ROX RX1510 versions prior to V2.16.5 RUGGEDCOM ROX RX1511 versions prior to V2.16.5 RUGGEDCOM ROX RX1512 versions prior to V2.16.5 RUGGEDCOM ROX RX1524 versions prior to V2.16.5 RUGGEDCOM ROX RX1536 versions prior to V2.16.5 RUGGEDCOM ROX RX5000 versions prior to V2.16.5
Description: A vulnerability has been identified in the tcpdump tool in the web interface of affected devices, which is vulnerable to command injection due to missing server-side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.
Recommendations: For all affected versions, update to version V2.16.5 or later to resolve the issue. As a temporary workaround, consider disabling the tcpdump tool in the web interface until a patch is available. Restrict access to the web interface to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-06605
CVE-2025-33024

Affected Products

Ruggedcom Rox Mx5000
Ruggedcom Rox Rx1400
Ruggedcom Rox Rx1500
Ruggedcom Rox Rx1501
Ruggedcom Rox Rx1510
Ruggedcom Rox Rx1511
Ruggedcom Rox Rx1512
Ruggedcom Rox Rx1524
Ruggedcom Rox Rx1536
Tcpdump