DomainFork
Markets
MarketsCompaniesCryptoCommoditiesIslamic Finance
Money
Personal FinanceProperty
World
MalaysiaASEANAsiaWorld
Business
TechnologyStartupsOpinion
Intelligence
AI EdgeOSINT Desk
Media
VideoAudioLifestyle
Breaking
The Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million7/22/2026Mendag Kunjungi UMKM Coklat nDalam dan Base Artisan di YogyakartaMendag Menjadi Pembicara Utama pada the 9th Indonesia International Cocoa Conference (IICC) 2026ກອງປະຊຸມປຶກສາຫາລື ກ່ຽວກັບ ບົດສະຫຼຸບຂໍ້ມູນສະຖິຕິ ສຳລັບ ການຈັດຕັ້ງປະຕິບັດແຜນພັດທະນາເສດຖະກິດ-ສັງຄົມແຫ່ງຊາດ ຄັ້ງທີ X ປະຈຳ 6 ເດືອນຕົ້ນປີ 2026 ແລະ ຄາດຄະເນ 6 ເດືອນທ້າຍປີ 2026The Year in ReviewAPI Latency Improvements and Revised SLOsTop cryptocurrencies lower; Bitcoin drops below $65,000 levelOil prices hit $100 for the first time since May - BBCFull CircleRickson Goh shows how you deal with a pandemicAMRO Cafe Seminar: Who Takes the Hit? The Uneven Impacts of Generative AI on Labor Demand Across CountriesDOF completes sale of Makati property for PhP1 Billion, boosts revenues for national developmentAMRO Cafe Seminar SeriesMural bertema edukasi di Kampung Mutihan Soloประกาศรายชื่อผู้ผ่านการสอบสัมภาษณ์ ตำแหน่งหมายเลข 101, 104, 105 และ 106AOT เดินหน้าต้านทุจริต เปิดเวทีสร้างค่านิยมสุจริต ตอกย้ำจุดยืนไม่เอาคอร์รัปชันทุกรูปแบบThe Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million7/22/2026Mendag Kunjungi UMKM Coklat nDalam dan Base Artisan di YogyakartaMendag Menjadi Pembicara Utama pada the 9th Indonesia International Cocoa Conference (IICC) 2026ກອງປະຊຸມປຶກສາຫາລື ກ່ຽວກັບ ບົດສະຫຼຸບຂໍ້ມູນສະຖິຕິ ສຳລັບ ການຈັດຕັ້ງປະຕິບັດແຜນພັດທະນາເສດຖະກິດ-ສັງຄົມແຫ່ງຊາດ ຄັ້ງທີ X ປະຈຳ 6 ເດືອນຕົ້ນປີ 2026 ແລະ ຄາດຄະເນ 6 ເດືອນທ້າຍປີ 2026The Year in ReviewAPI Latency Improvements and Revised SLOsTop cryptocurrencies lower; Bitcoin drops below $65,000 levelOil prices hit $100 for the first time since May - BBCFull CircleRickson Goh shows how you deal with a pandemicAMRO Cafe Seminar: Who Takes the Hit? The Uneven Impacts of Generative AI on Labor Demand Across CountriesDOF completes sale of Makati property for PhP1 Billion, boosts revenues for national developmentAMRO Cafe Seminar SeriesMural bertema edukasi di Kampung Mutihan Soloประกาศรายชื่อผู้ผ่านการสอบสัมภาษณ์ ตำแหน่งหมายเลข 101, 104, 105 และ 106AOT เดินหน้าต้านทุจริต เปิดเวทีสร้างค่านิยมสุจริต ตอกย้ำจุดยืนไม่เอาคอร์รัปชันทุกรูปแบบ
Home/OSINT
Economy

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 .

Source: Palo Alto Unit 42 · July 23, 2026 at 10:55 PM · AI-assisted report

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
DomainFork
Image: unit42.paloaltonetworks.com

KUALA LUMPUR, 24 JULY 2026 —

Listen to this article

DomainFork Audio · read aloud

Headline: Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Lead: A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 . Body: We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949). These vulnerabilities could collectively transform a vital network security device into a platform for malicious activity, severely threatening the integrity and availability of the industrial network. Siemens has released security advisories SSA-973901 , SSA-078743 and SSA-081142 to address these issues, which recommend that customers update their affected ROX II devices to firmware version V2.17.1. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team . The Palo Alto Networks OT Threat Research Lab and Siemens partnered to advance the security and resilience of critical infrastructure through collaborative vulnerability research on the Ruggedcom ROX II platform. We combined the OT Threat Research Lab’s expertise in industrial cybersecurity research with Siemens’ deep product knowledge and the coordination capabilities of Siemens ProductCERT. These teams worked together to identify, validate, remediate and responsibly disclose security vulnerabilities. This collaboration reflects the growing importance of industry partnerships in securing OT environments. As critical infrastructure enters the AI era, organizations must work together more closely than ever to address emerging threats, accelerate vulnerability remediation and strengthen the security of the technologies that support essential services worldwide. This partnership demonstrates how coordinated research and responsible disclosure can help build a more resilient and secure future for critical infrastructure. The modern OT environment is a complex network of devices working in concert. At the heart of this connectivity are OT switches, which act as the nervous systems of industrial networks, directing communication between critical assets like human-machine interfaces (HMIs) and programmable logic controllers (PLCs). Protecting the integrity and availability of these switches is paramount for any industrial operation, be it a factory floor or a power plant. For instance, a properly configured OT switch provides crucial network segmentation, which enhances security by isolating different parts of the network while still allowing necessary communication. However, OT switches designed to secure the network can themselves become attack surfaces. A common misconception is that because these devices are often air-gapped or sit on isolated networks, they’re inherently safe. In reality, they are just as susceptible to software vulnerabilities as any other IT equipment, allowing an unprivileged attacker to exploit software flaws, escalate privileges and disrupt OT communication. This threat research article demonstrates how seemingly benign flaws can be exploited to initiate a chain of events. In this case, this could lead to full control of the critical OT switch operating system ROX II. The first vulnerability, CVE-2025-40948 , is an arbitrary file disclosure vulnerability. While not immediately devastating, this flaw provides vital intelligence by revealing sensitive information on the switch operating system (OS), from password hashes to network topology data. This initial foothold is a crucial step in a sophisticated attack. The second vulnerability, CVE-2025-40947 , is the pivotal privilege escalation flaw. We identified this vulnerability by carefully analyzing the switch’s feature key functionality, a mechanism designed to unlock optional capabilities. By reverse-engineering this feature, we discovered a way to exploit its internal logic and gain root access. This vulnerability grants an attacker total control, bypassing available security measures and transforming the switch into a platform for malicious activity. The third vulnerability, CVE-2025-40949 , solidifies the attacker’s control by exploiting the switch’s task scheduling functionality. An authenticated attacker can schedule malicious scripts to run with root privilege at predetermined intervals, ensuring persistence even after a reboot. This allows for ongoing malicious activity, such as data exfiltration or denial-of-service attacks, making the compromise difficult to detect or remove. During the initial analysis of the switch’s publicly available firmware, we worked with Siemens researchers and located a key configuration file associated with a privileged daemon. This file is used by a management and configuration daemon running with root privileges on the switch’s operating system. As a root-privileged process, it can perform any action on the system, including reading and writing any file. The xz command is a common Linux utility primarily used for compressing files into the XZ format with a highly effective compression algorithm. However, xz can be used with specific parameters to function like the standard Linux cat command, which is used to print files to standard output. By supplying the parameters -f, -c and -d at the same time, an attacker can instruct xz to view file contents. The CVE-2025-40948 vulnerability lies in the privileged daemon executing the xz command with user-provided parameters. Since the process runs as root, an attacker can pass any file path to xz , allowing it to read any file on the file system, including those normally inaccessible to regular users. This insecure configuration creates a significant arbitrary file disclosure vulnerability. An attacker can leverage this to: In the case of the ROX II switch, this oversight would have allowed an attacker to leak the contents of any file on the file system. This highlights the importance of carefully vetting all commands executed by privileged processes and ensuring that user input is never used to construct commands insecurely. To understand CVE-2025-40947, we must first understand how the Siemens feature key mechanism works. A feature key is a cryptographically signed license that enables specific functionalities on the… (AI-assisted rewrite, based on the original source)

Malaysia Impact

Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.

Suggested Reads

The Computer That Helped Win World War II7/23/2026Aneka Jaringan’s 9M26 PAT Plunges 91.6% To RM0.37 MillionAlpha IVF Declares 0.6 Sen Dividend Despite FY26 PATMI Falls 6.8% To RM53.6 Million

Analyst Consensus — This Week

Neutral6.4/10AI sentiment across 98 stories · not investment advice

The Daily Brief · Free

Five market signals.
Five minutes. Every morning.

AI-curated intelligence on Malaysia, ASEAN, and global markets — before the opening bell.

  • ✓ KLCI, ringgit & sector movers
  • ✓ The AI Edge sentiment read
  • ✓ No spam — one email, weekday mornings

Free daily market briefing. No spam, unsubscribe anytime.

DomainFork

Malaysian financial intelligence — AI-assisted coverage of finance, economics, technology, and open-source data across Malaysia, ASEAN, and the world.

Sections

  • Malaysia
  • ASEAN
  • Asia
  • World
  • Tech
  • Markets

Intelligence

  • AI Daily Briefing
  • OSINT Desk
  • Video
  • Audio

Company

  • About Us
  • Editorial Standards
  • Advertise
  • Contact the Desk

Disclaimer: DomainFork provides financial, economic, technology, and OSINT information for general education and research. AI summaries, sentiment scores, and market data are not investment advice. Consult a licensed professional before making financial decisions.

© 2026 DomainFork. All rights reserved.

Powered by: Codint Technology : codint.io