CVE-2025-40938: Siemens SIMATIC Cn 4100 Firmware

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability.

Affected products

  • Siemens SIMATIC Cn 4100 Firmware: before 4.0.1 (fixed in 4.0.1)

Published 2025-12-09. Last modified 2026-10-07.