PT-2025-49826 · Ruggedcom · Ruggedcom Rox Ii

Published

2025-12-09

·

Updated

2025-12-14

·

CVE-2024-56835

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RUGGEDCOM ROX II versions prior to 2.17.0
Description A code injection issue exists in the DHCP Server configuration file of RUGGEDCOM ROX II devices. Successful exploitation could allow an attacker to execute arbitrary code, potentially gaining root access to the system by spawning a reverse shell.
Recommendations Update to version 2.17.0 or later.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15625
CVE-2024-56835

Affected Products

Ruggedcom Rox Ii