RuggedCOM web TLS cert upload CVE-2025-40935: auth remote crash <v5.10.1
CVE-2025-40935 Published on December 9, 2025
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100P (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2288 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300 V5.X (All versions < V5.10.1), RUGGEDCOM RSG2300P V5.X (All versions < V5.10.1), RUGGEDCOM RSG2488 V5.X (All versions < V5.10.1), RUGGEDCOM RSG907R (All versions < V5.10.1), RUGGEDCOM RSG908C (All versions < V5.10.1), RUGGEDCOM RSG909R (All versions < V5.10.1), RUGGEDCOM RSG910C (All versions < V5.10.1), RUGGEDCOM RSG920P V5.X (All versions < V5.10.1), RUGGEDCOM RSL910 (All versions < V5.10.1), RUGGEDCOM RST2228 (All versions < V5.10.1), RUGGEDCOM RST2228P (All versions < V5.10.1), RUGGEDCOM RST916C (All versions < V5.10.1), RUGGEDCOM RST916P (All versions < V5.10.1). Affected devices do not properly validate input during the TLS certificate upload process of the web service. This could allow an authenticated remote attacker to trigger a device crash and reboot, leading to a temporary Denial of Service on the device.
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Versions
Siemens RUGGEDCOM RMC8388 V5.X:- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
- Before V5.10.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.