Unit 42
Read post

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Networks Unit 42 and Siemens jointly disclosed three chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II OT switches. The exploit chain starts with arbitrary file disclosure via a misconfigured xz utility running as root, escalates to full root access through command injection in the feature key validation function (which passes unsanitized input to system()), and achieves persistence by injecting malicious commands into the root cron table via the web management task scheduler. CVSS scores range from 6.8 to 9.1. Siemens has released firmware V2.17.1 to address all three issues. Palo Alto Networks also provides virtual patching signatures via Advanced Threat Prevention as a compensating control.

    #security#zero-day
Jul 17•14m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryPartnership OverviewThe Role of OT SwitchesThe Impact: From Innocuous to HostileExploit Chain Part 1: Exploiting CVE-2025-40948, Then Misusing xz for File System Information DisclosureExploit Chain Part 2: Exploiting CVE-2025-40947, the Feature Key for Root AccessExploit Chain Part 3: Exploiting CVE-2025-40949, Persistence via System SchedulingExploit Chain Proof of Concept (PoC)ConclusionIndicators of BehaviorAdditional Resources
610 Impressions
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard