CVE-2025-40761: High severity RUGGEDCOM ROX MX5000 vulnerability
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All versions), RUGGEDCOM ROX RX1501 (All versions), RUGGEDCOM ROX RX1510 (All versions), RUGGEDCOM ROX RX1511 (All versions), RUGGEDCOM ROX RX1512 (All versions), RUGGEDCOM ROX RX1524 (All versions), RUGGEDCOM ROX RX1536 (All versions), RUGGEDCOM ROX RX5000 (All versions). Affected devices do not properly limit access through its Built-In-Self-Test (BIST) mode. This could allow an attacker with physical access to the serial interface to bypass authentication and get access to a root shell on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40761?
CVE-2025-40761 is classified as a critical vulnerability affecting multiple RUGGEDCOM ROX devices.
How do I fix CVE-2025-40761?
To fix CVE-2025-40761, update your RUGGEDCOM ROX devices to the latest firmware version provided by RUGGEDCOM.
What devices are affected by CVE-2025-40761?
CVE-2025-40761 affects various RUGGEDCOM ROX models including MX5000, RX1400, RX1500, RX1501, RX1510, RX1511, RX1512, RX1524, RX1536, and RX5000.
When was CVE-2025-40761 disclosed?
CVE-2025-40761 was disclosed in 2025, following the identification of the vulnerability in RUGGEDCOM ROX devices.
What are the risks of not addressing CVE-2025-40761?
Not addressing CVE-2025-40761 may expose your network to potential attacks leading to unauthorized access or disruptions.