logo

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

ID: 99afba6e-3531-56ed-8df1-33e801aad134

STIX ID: report--99afba6e-3531-56ed-8df1-33e801aad134

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-23

Author: Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira

...
...

Palo Alto Networks in partnership with Siemens disclosed a chained set of three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational-technology switches that together allow arbitrary file disclosure via misuse of xz, root privilege escalation through feature-key command injection, and persistent root execution via task-scheduler injection; Siemens released advisories and a firmware update (V2.17.1) while Palo Alto recommends defenses and provides detection/mitigation guidance and indicators of behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.