Zero-day chain in Siemens ROX II

Article by Nacata Security, 23/07/2026

Did you know that the switch protecting your industrial network could be the entry point?

Three zero-day vulnerabilities chained together open full root access on Siemens ROX II switches.

Industrial switches are the nervous system of factories and power plants: they manage which systems communicate with which, and isolate critical zones.

Believing that an isolated network protects these devices is a widespread misconception among industrial operators. The reality, however, completely disproves that idea.

Image illustrating the mechanics of privilege escalation: a mechanical humanoid with a root access terminal on its chest, a hand inserting a forged license key, and injected commands flowing toward the core of the system.
Privilege escalation

Three separate flaws, one single path to total control.

The first link is CVE-2025-40948, a file disclosure vulnerability. The attacker exploits the fact that a process running with maximum privileges executes the xz compression tool by passing it parameters that turn it into a file reader. This allows the extraction of password hashes and network maps without anyone noticing. Nothing is destroyed yet: it simply collects the information that will be needed later.

The master key was hidden in the licensing system.

The second flaw, CVE-2025-40947, resides in the feature key mechanism: signed licenses that activate switch options. By reverse-engineering the library that processes them, researchers found that the verification function inserts the received signature into a system command with no filtering whatsoever. An attacker can inject their own instructions there and instantly obtain a root shell.

CVSS 9.1: the highest score among the three chained vulnerabilities.

The third flaw, CVE-2025-40949, completes the chain. The attacker manipulates the switch’s task scheduler through the web management interface and injects commands that execute with root privileges on every scheduled cycle. Persistence is maintained even after full device reboots, without the attacker needing to reconnect.

Image illustrating the general pattern: a row of identical industrial devices standing like dominoes at the edge of a cliff, the first one already falling and the rest about to follow, with a corrupted web management panel floating in the background.
Risk pattern

This pattern is not unique to this switch.

Any OT device with a web management interface and privileged processes that accept user input can be subject to a similar chain.

The combination of elevated privileges, unfiltered input, and web access multiplies the risk exponentially.

The three vulnerabilities receive CVSS scores of 6.8, 7.5, and 9.1, classifying the complete chain as critical according to international standards.

The patch already exists, but applying it takes time.

Siemens released firmware V2.17.1 to address all three flaws. In industrial environments, updating a switch requires maintenance windows, compatibility testing, and coordination with processes that cannot be interrupted without prior planning.

Defense in depth has never been more necessary.

While the update is being rolled out, industrial security teams must apply compensating controls. A next-generation firewall with advanced threat prevention can block known attack vectors through specific signatures. Continuous visibility into OT devices makes it possible to detect anomalous behavior—such as new scheduled tasks or unusual file reads—before the damage becomes irreversible.

Collaboration between manufacturer and researchers accelerated the fix.

Palo Alto Networks and Siemens worked together throughout the entire process: researchers provided the technical analysis and firmware reverse engineering, while Siemens coordinated validation and responsible disclosure. This model reduces the exposure window for all operators of the same device worldwide.

Image illustrating the collaboration between researchers and manufacturer: two figures jointly sealing the cracks of an industrial device with golden light, symbolizing responsible disclosure and coordinated remediation.
Responsible collaboration

The greatest risk is not knowing you are exposed.

Many industrial operators assume their networks are isolated and do not monitor their OT switches. Without visibility, a three-flaw chain like this can operate for weeks without triggering any internal or external alert.

Updating the firmware is the mandatory first step.

Version V2.17.1 of the ROX II firmware fixes all three CVEs. Before applying it, it is advisable to audit the switch logs for unusual access, unrecognized scheduled tasks, or bulk reads of system files. If anything seems out of place, treat it as an indicator of compromise.

A compromised switch can compromise the entire plant.

From that device, an attacker can move laterally, intercept communications between critical systems, or launch attacks that bring the entire production line to a halt. The impact surface extends far beyond the switch itself.

What you can do

  • Update the ROX II firmware to version V2.17.1 as soon as possible.
  • Audit scheduled tasks and switch logs for anomalies.
  • Apply network segmentation and active monitoring on OT devices.

Do you know exactly which privileged processes are running right now on your industrial network?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Technical

In-depth explanations of how attack and defense techniques work in cybersecurity: from intrusion methods to malware analysis.

Educational, analytical content, useful to understand the “how” beyond the news of the moment.



RATING


8.3



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.