High severity8.3NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2025-40937
CVE-2025-40937
Description
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authenticated attacker to execute arbitrary code with limited privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:*Range: <4.0.1
<V4.0.1+ 1 more
- (no CPE)range: <V4.0.1
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/html/ssa-416652.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.