Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Researchers from Palo Alto Networks' Unit 42 have uncovered a chain of three zero-day vulnerabilities in Siemens ROX II industrial switches, which could allow attackers to gain full root access and maintain persistent control over the devices. The flaws—CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949—range from arbitrary file disclosure to command injection and system persistence. Siemens has issued security advisories recommending an update to firmware version V2.17.1. These vulnerabilities underscore the need for strong input validation and secure coding practices in operational technology (OT) environments.
Executive Summary
We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure.
This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949).…