PT-2025-49841 · Ruggedcom · Ruggedcom Rsg2300+17
Published
2025-12-09
·
Updated
2025-12-09
·
CVE-2025-40935
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
RUGGEDCOM RMC8388 versions prior to 5.10.1
RUGGEDCOM RS416Pv2 versions prior to 5.10.1
RUGGEDCOM RS416v2 versions prior to 5.10.1
RUGGEDCOM RS900 (32M) versions prior to 5.10.1
RUGGEDCOM RS900G (32M) versions prior to 5.10.1
RUGGEDCOM RSG2100 (32M) versions prior to 5.10.1
RUGGEDCOM RSG2100P (32M) versions prior to 5.10.1
RUGGEDCOM RSG2288 versions prior to 5.10.1
RUGGEDCOM RSG2300 versions prior to 5.10.1
RUGGEDCOM RSG2300P versions prior to 5.10.1
RUGGEDCOM RSG2488 versions prior to 5.10.1
RUGGEDCOM RSG907R versions prior to 5.10.1
RUGGEDCOM RSG908C versions prior to 5.10.1
RUGGEDCOM RSG909R versions prior to 5.10.1
RUGGEDCOM RSG910C versions prior to 5.10.1
RUGGEDCOM RSG920P versions prior to 5.10.1
RUGGEDCOM RSL910 versions prior to 5.10.1
RUGGEDCOM RST2228 versions prior to 5.10.1
RUGGEDCOM RST2228P versions prior to 5.10.1
RUGGEDCOM RST916C versions prior to 5.10.1
RUGGEDCOM RST916P versions prior to 5.10.1
Description
The affected devices do not properly validate input during the TLS certificate upload process of the web service. This can allow an authenticated remote attacker to trigger a device crash and reboot, resulting in a temporary Denial of Service.
Recommendations
RUGGEDCOM RMC8388 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RS416Pv2 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RS416v2 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RS900 (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RS900G (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2100 (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2100P (32M) versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2288 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2300 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2300P versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG2488 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG907R versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG908C versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG909R versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG910C versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSG920P versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RSL910 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RST2228 versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RST2228P versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RST916C versions prior to 5.10.1 should be updated to version 5.10.1 or later.
RUGGEDCOM RST916P versions prior to 5.10.1 should be updated to version 5.10.1 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruggedcom Rmc8388
Ruggedcom Rs416Pv2
Ruggedcom Rs900
Ruggedcom Rs900G
Ruggedcom Rsg2100
Ruggedcom Rsg2100P
Ruggedcom Rsg2288
Ruggedcom Rsg2300
Ruggedcom Rsg2300P
Ruggedcom Rsg2488
Ruggedcom Rsg907R
Ruggedcom Rsg908C
Ruggedcom Rsg909R
Ruggedcom Rsg910C
Ruggedcom Rsg920P
Ruggedcom Rsl910
Ruggedcom Rst2228
Ruggedcom Rst916C