cbcvebase.
CVE-2025-40935
published 2025-12-09

CVE-2025-40935: A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.23%
13.3th percentile
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100P (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2288 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300P V5.X (All versions < V5.10.1), RUGGEDCOM RSG2488 V5.X (All versions < V5.10.1), RUGGEDCOM RSG907R (All versions < V5.10.1), RUGGEDCOM RSG908C (All versions < V5.10.1), RUGGEDCOM RSG909R (All versions < V5.10.1), RUGGEDCOM RSG910C (All versions < V5.10.1), RUGGEDCOM RSG920P V5.X (All versions < V5.10.1), RUGGEDCOM RSL910 (All versions < V5.10.1), RUGGEDCOM RST2228 (All versions < V5.10.1), RUGGEDCOM RST2228P (All versions < V5.10.1), RUGGEDCOM RST916C (All versions < V5.10.1), RUGGEDCOM RST916P (All versions < V5.10.1). Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.

Affected

21 ranges
VendorProductVersion rangeFixed in
siemensruggedcom_rmc8388_v5.x< V5.10.1V5.10.1
siemensruggedcom_rs416pv2_v5.x< V5.10.1V5.10.1
siemensruggedcom_rs416v2_v5.x< V5.10.1V5.10.1
siemensruggedcom_rs900_v5.x< V5.10.1V5.10.1
siemensruggedcom_rs900g_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2100_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2100p_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2288_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2300_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2300p_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg2488_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsg907r< V5.10.1V5.10.1
siemensruggedcom_rsg908c< V5.10.1V5.10.1
siemensruggedcom_rsg909r< V5.10.1V5.10.1
siemensruggedcom_rsg910c< V5.10.1V5.10.1
siemensruggedcom_rsg920p_v5.x< V5.10.1V5.10.1
siemensruggedcom_rsl910< V5.10.1V5.10.1
siemensruggedcom_rst2228< V5.10.1V5.10.1
siemensruggedcom_rst2228p< V5.10.1V5.10.1
siemensruggedcom_rst916c< V5.10.1V5.10.1
siemensruggedcom_rst916p< V5.10.1V5.10.1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.