PT-2025-49841 · Ruggedcom · Ruggedcom Rsg2300+17

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-40935

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions RUGGEDCOM RMC8388 versions prior to 5.10.1 RUGGEDCOM RS416Pv2 versions prior to 5.10.1 RUGGEDCOM RS416v2 versions prior to 5.10.1 RUGGEDCOM RS900 (32M) versions prior to 5.10.1 RUGGEDCOM RS900G (32M) versions prior to 5.10.1 RUGGEDCOM RSG2100 (32M) versions prior to 5.10.1 RUGGEDCOM RSG2100P (32M) versions prior to 5.10.1 RUGGEDCOM RSG2288 versions prior to 5.10.1 RUGGEDCOM RSG2300 versions prior to 5.10.1 RUGGEDCOM RSG2300P versions prior to 5.10.1 RUGGEDCOM RSG2488 versions prior to 5.10.1 RUGGEDCOM RSG907R versions prior to 5.10.1 RUGGEDCOM RSG908C versions prior to 5.10.1 RUGGEDCOM RSG909R versions prior to 5.10.1 RUGGEDCOM RSG910C versions prior to 5.10.1 RUGGEDCOM RSG920P versions prior to 5.10.1 RUGGEDCOM RSL910 versions prior to 5.10.1 RUGGEDCOM RST2228 versions prior to 5.10.1 RUGGEDCOM RST2228P versions prior to 5.10.1 RUGGEDCOM RST916C versions prior to 5.10.1 RUGGEDCOM RST916P versions prior to 5.10.1
Description The affected devices do not properly validate input during the TLS certificate upload process of the web service. This can allow an authenticated remote attacker to trigger a device crash and reboot, resulting in a temporary Denial of Service.
Recommendations RUGGEDCOM RMC8388 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RS416Pv2 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RS416v2 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RS900 (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RS900G (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2100 (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2100P (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2288 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2300 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2300P versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG2488 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG907R versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG908C versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG909R versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG910C versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSG920P versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RSL910 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RST2228 versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RST2228P versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RST916C versions prior to 5.10.1 should be updated to version 5.10.1 or later. RUGGEDCOM RST916P versions prior to 5.10.1 should be updated to version 5.10.1 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-15662
CVE-2025-40935

Affected Products

Ruggedcom Rmc8388
Ruggedcom Rs416Pv2
Ruggedcom Rs900
Ruggedcom Rs900G
Ruggedcom Rsg2100
Ruggedcom Rsg2100P
Ruggedcom Rsg2288
Ruggedcom Rsg2300
Ruggedcom Rsg2300P
Ruggedcom Rsg2488
Ruggedcom Rsg907R
Ruggedcom Rsg908C
Ruggedcom Rsg909R
Ruggedcom Rsg910C
Ruggedcom Rsg920P
Ruggedcom Rsl910
Ruggedcom Rst2228
Ruggedcom Rst916C