Siemens ROX II industrial switch zero-days can be chained for persistent root access

Researchers say three zero-day flaws in Siemens ROX II industrial network switches can let an attacker take full control of the device and keep that access after a reboot. Palo Alto Networks said the chain combines arbitrary file disclosure CVE-2025-40948, command injection CVE-2025-40947, and code execution via the web-management task scheduler CVE-2025-40949 to achieve persistent root-level compromise.
Why it matters: Organizations using Siemens ROX II in operational technology or industrial networks should treat this as urgent because a successful attack could hand over deep control of network equipment that supports physical operations. Identify exposed ROX II devices, apply Siemens mitigations or patches when available, and restrict management access immediately.

Sources

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
SecurityWeek News 2026.07.24 100% relevant
This article establishes a concrete vulnerability story by summarizing a specific three-CVE exploit chain affecting Siemens ROX II industrial switches and its persistence impact.
← Back to all stories