PT-2025-49829 · Ruggedcom · Ruggedcom Rox Ii

Published

2025-12-09

·

Updated

2025-12-14

·

CVE-2024-56838

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RUGGEDCOM ROX II versions prior to 2.17.0
Description The SCEP client within the affected devices does not properly validate multiple fields during secure certificate enrollment. This could allow an attacker to execute arbitrary code with root privileges.
Recommendations Update to version 2.17.0 or later.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15628
CVE-2024-56838

Affected Products

Ruggedcom Rox Ii