CVE-2025-40833: Siemens Ie/pb Link Ha

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual restart is required to recover the system.

Affected products

  • Siemens Ie/pb Link Ha: before V4.1.2 (fixed in V4.1.2)
  • Siemens Ie/pb Link Pn Io: any version
  • Siemens Ruggedcom RM1224 LTE4G Eu: before V8.3 (fixed in V8.3)
  • Siemens Ruggedcom RM1224 LTE4G Nam: before V8.3 (fixed in V8.3)
  • Siemens Scalance m804pb: before V8.3 (fixed in V8.3)
  • Siemens Scalance m812-1 Adsl-Router: before V8.3 (fixed in V8.3)
  • Siemens Scalance m816-1 Adsl-Router: before V8.3 (fixed in V8.3)
  • Siemens Scalance m826-2 Shdsl-Router: before V8.3 (fixed in V8.3)
  • Siemens Scalance m874-2: before V8.3 (fixed in V8.3)
  • Siemens Scalance m874-3: before V8.3 (fixed in V8.3)
  • Siemens Scalance m874-3 3g-Router Cn: before V8.3 (fixed in V8.3)
  • Siemens Scalance m876-3: before V8.3 (fixed in V8.3)
  • Siemens Scalance m876-3 Rok: before V8.3 (fixed in V8.3)
  • Siemens Scalance m876-4: before V8.3 (fixed in V8.3)
  • Siemens Scalance m876-4 Eu: before V8.3 (fixed in V8.3)
  • Siemens Scalance m876-4 Nam: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUB852-1 a1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUB852-1 b1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM853-1 a1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM853-1 b1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM853-1 Eu: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM856-1 a1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM856-1 b1: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM856-1 Cn: before V8.3 (fixed in V8.3)
  • Siemens Scalance MUM856-1 Eu: before V8.3 (fixed in V8.3)
  • and 219 more

Published 2026-05-12. Last modified 2026-08-11.