# Siemens RUGGEDCOM RST2428P SINEC OS Patched

Published: 2026-07-07 · Severity: medium · Sectors: manufacturing, transportation, energy, healthcare, financial-services, government-national
Canonical: https://vorant.io/reports/169038ef-edf3-5ead-b80a-4f7f76d1fdf1/siemens-ruggedcom-rst2428p-sinec-os-patched

> Siemens fixed dozens of third-party library and Linux kernel vulnerabilities in SINEC OS affecting RUGGEDCOM RST2428P switches, urging an update to V4.0.

Siemens has disclosed a large batch of vulnerabilities affecting SINEC OS versions prior to V4.0, impacting the RUGGEDCOM RST2428P industrial switch. The flaws originate from bundled open-source components including GNU elfutils, GLib, ncurses, libxml2, curl, OpenSSL, Lodash, and the Linux kernel itself, covering issues such as memory corruption, buffer overflows, integer overflows, path traversal, prototype pollution, out-of-bounds reads/writes, and a timing side-channel in SM2 signature computations on ARM64 platforms.

Most of these vulnerabilities require local access or high attack complexity, and several (e.g., CVE-2025-8732, CVE-2025-9232) are assessed as low-to-moderate severity by their respective upstream maintainers, with limited real-world exploitability. However, a subset—including CVE-2025-1352 (critical-rated memory corruption in elfutils) and CVE-2025-9086 (curl cookie handling flaw)—have public exploit disclosures available, though practical exploitation remains difficult. No active exploitation against Siemens products has been reported.

Siemens recommends updating affected RUGGEDCOM RST2428P devices to SINEC OS V4.0 or later, which resolves the full set of inherited third-party component vulnerabilities. Given the product's deployment across critical manufacturing, transportation, energy, healthcare, financial services, and government sectors worldwide, organizations operating these switches should prioritize patching as part of routine industrial control system maintenance, though the overall risk profile is consistent with a standard third-party component roll-up advisory rather than an actively exploited threat.

## Mentioned in this report

- Vulnerabilities: CVE-2025-10966, CVE-2025-13465, CVE-2025-1352, CVE-2025-13601, CVE-2025-1376, CVE-2025-39913, CVE-2025-40214, CVE-2025-40248, CVE-2025-40250, CVE-2025-40251, CVE-2025-40252, CVE-2025-40254, CVE-2025-6052, CVE-2025-6141, CVE-2025-6170, CVE-2025-7039, CVE-2025-8732, CVE-2025-9086, CVE-2025-9230, CVE-2025-9231, CVE-2025-9232

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/169038ef-edf3-5ead-b80a-4f7f76d1fdf1/siemens-ruggedcom-rst2428p-sinec-os-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
