CVE-2025-40817: Siemens Logo! 12/24rce

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo (6ED1052-2CC08-0BA2) (All versions), LOGO! 24RCE (6ED1052-1HB08-0BA2) (All versions), LOGO! 24RCEo (6ED1052-2HB08-0BA2) (All versions), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA2) (All versions), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA2) (All versions), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA2) (All versions), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA2) (All versions), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA2) (All versions), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA2) (All versions), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA2) (All versions), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA2) (All versions). Affected devices do not conduct certain validations when interacting with them. This could allow an unauthenticated remote attacker to change time of the device, which means the device could behave differently.

Affected products

  • Siemens Logo! 12/24rce: any version
  • Siemens Logo! 12/24rceo: any version
  • Siemens Logo! 230rce: any version
  • Siemens Logo! 230rceo: any version
  • Siemens Logo! 24ce: any version
  • Siemens Logo! 24ceo: any version
  • Siemens Logo! 24rce: any version
  • Siemens Logo! 24rceo: any version
  • Siemens Siplus Logo! 12/24rce: any version
  • Siemens Siplus Logo! 12/24rceo: any version
  • Siemens Siplus Logo! 230rce: any version
  • Siemens Siplus Logo! 230rceo: any version
  • Siemens Siplus Logo! 24ce: any version
  • Siemens Siplus Logo! 24ceo: any version
  • Siemens Siplus Logo! 24rce: any version
  • Siemens Siplus Logo! 24rceo: any version

Published 2025-11-11. Last modified 2026-06-17.