Palo Alto Networks Unit 42 and Siemens jointly disclosed three chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II OT switches. The exploit chain starts with arbitrary file disclosure via a misconfigured xz utility running as root, escalates to full root access through command injection in the feature key validation function (which passes unsanitized input to system()), and achieves persistence by injecting malicious commands into the root cron table via the web management task scheduler. CVSS scores range from 6.8 to 9.1. Siemens has released firmware V2.17.1 to address all three issues. Palo Alto Networks also provides virtual patching signatures via Advanced Threat Prevention as a compensating control.