LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-40949

CVE-2025-40949 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: May 12, 2026

RUGGEDCOM ROX - Command Injection

Published: May 12, 2026Updated: May 12, 2026Remote Exploitable

Overview

RUGGEDCOM ROX devices < V2.17.1 contain a command injection caused by improper sanitization of user input in the Scheduler Web UI, letting authenticated remote attackers execute arbitrary commands as root.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 17.3%(Probability of exploitation in next 30 days)

Impact

Authenticated remote attackers can execute arbitrary commands with root privileges, leading to full system compromise.

Mitigation

Update to version V2.17.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

šŸ”“ CVE-2025-40949 - Critical (9.1) A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGED... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-40949/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

šŸ”“ CVE-2025-40949 - Critical (9.1) A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGED... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-40949/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-40949
Severity
Critical
CVSS Score
9.1
Type
command_injection
Status
unconfirmed
EPSS
17.3%
Social Posts
2

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Score

17.3%Probability of exploitation in the next 30 days