# CVE-2026-41918

## Summary

- **CVE ID:** CVE-2026-41918
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-525
- **Published:** Jun 2, 2026
- **Last Modified:** Jun 2, 2026

## Description

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.

## Affected Products

- Siemens — RUGGEDCOM RST2428P (0)

## References

- [CNA](https://cert-portal.siemens.com/productcert/html/ssa-253495.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._