Browser Cache Sensitive Data Leakage in RUGGEDCOM RST2428P <4.0
CVE-2026-41918 Published on June 2, 2026

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.

NVD

Weakness Type

Use of Web Browser Cache Containing Sensitive Information

The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.


Affected Versions

Siemens RUGGEDCOM RST2428P: