CVE-2025-40593: Siemens SIMATIC Cn 4100 Firmware

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files in the SFTP folder of the device. This could allow an attacker to cause a denial of service condition.

Affected products

  • Siemens SIMATIC Cn 4100 Firmware: before 4.0 (fixed in 4.0)

Published 2025-07-08. Last modified 2026-06-17.