CVE-2025-40815: Siemens Logo! 12/24rce

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo (6ED1052-2CC08-0BA2) (All versions), LOGO! 24RCE (6ED1052-1HB08-0BA2) (All versions), LOGO! 24RCEo (6ED1052-2HB08-0BA2) (All versions), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA2) (All versions), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA2) (All versions), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA2) (All versions), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA2) (All versions), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA2) (All versions), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA2) (All versions), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA2) (All versions), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA2) (All versions). Affected devices do not properly validate the structure of TCP packets in several methods. This could allow an attacker to cause buffer overflows, get control over the instruction counter and run custom code.

Affected products

  • Siemens Logo! 12/24rce: any version
  • Siemens Logo! 12/24rceo: any version
  • Siemens Logo! 230rce: any version
  • Siemens Logo! 230rceo: any version
  • Siemens Logo! 24ce: any version
  • Siemens Logo! 24ceo: any version
  • Siemens Logo! 24rce: any version
  • Siemens Logo! 24rceo: any version
  • Siemens Siplus Logo! 12/24rce: any version
  • Siemens Siplus Logo! 12/24rceo: any version
  • Siemens Siplus Logo! 230rce: any version
  • Siemens Siplus Logo! 230rceo: any version
  • Siemens Siplus Logo! 24ce: any version
  • Siemens Siplus Logo! 24ceo: any version
  • Siemens Siplus Logo! 24rce: any version
  • Siemens Siplus Logo! 24rceo: any version

Published 2025-11-11. Last modified 2026-06-17.