CVE-2025-40939: Siemens SIMATIC Cn 4100 Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition.

Affected products

  • Siemens SIMATIC Cn 4100 Firmware: before 4.0.1 (fixed in 4.0.1)

Published 2025-12-09. Last modified 2026-10-07.