PT-2025-49827 · Ruggedcom · Ruggedcom Rox Ii

Published

2025-12-09

·

Updated

2025-12-14

·

CVE-2024-56836

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RUGGEDCOM ROX II versions prior to 2.17.0
Description A flaw exists in the RUGGEDCOM ROX II family that allows for the injection of additional configuration parameters during Dynamic DNS configuration. An attacker could potentially exploit this to create a reverse shell and obtain root access on a compromised system.
Recommendations Update to version 2.17.0 or later.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15626
CVE-2024-56836

Affected Products

Ruggedcom Rox Ii