Unit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.
exploited
PoC
ROX II OT switches +2
industrial-control-systems
ot-security
zero-day
privilege-escalation
command-injection
persistence
siemens
vulnerability-exploit
3r
4t
5c
updated