DEV Community

Cover image for Critical Authentication Bypass and Smuggling Flaws Impact Siemens RUGGEDCOM APE1808
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Critical Authentication Bypass and Smuggling Flaws Impact Siemens RUGGEDCOM APE1808

Summary

Siemens disclosed four vulnerabilities in RUGGEDCOM APE1808 devices, including a critical authentication bypass (CVE-2026-24858) that allows attackers to hijack devices via FortiCloud SSO. The flaws also include HTTP request smuggling and format string vulnerabilities that could lead to unauthorized code execution or policy bypass.

Take Action:

If you use RUGGEDCOM APE1808 devices with FortiOS, this is now urgent and important. The most critical item is a Fortinet flaw, and Fortinet is very much targeted by hackers. Update to version 7.4.11 ASAP. Isolation is not really a solution for a firewall that's designed operate between an insecure and secure networks.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)