CISA

Siemens RUGGEDCOM APE1808 Devices

From Cybersecurity and Infrastructure Security Agency ↗

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/

The following versions of Siemens RUGGEDCOM APE1808 Devices are affected:

RUGGEDCOM APE1808 vers:all/* (CVE-2026-0300)

Vendor

Equipment

Siemens

Siemens RUGGEDCOM APE1808 Devices

Out-of-bounds Write

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company...