LOGO! CMR2020/CMR2040 Firmware V2.1 Update: Procedure & Fixes

David Krause11 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

LOGO! CMR2020/CMR2040 Firmware V2.1 Update: Procedure, Enhancements, and Field Notes

The LOGO! CMR2020 (article number 6GK7142-7BX00-0AX0) and LOGO! CMR2040 (article number 6GK7142-7EX00-0AX0) are Siemens communication modules that provide remote monitoring, SMS alarming, e-mail notification, and VPN connectivity for the LOGO! 8 logic module family. Siemens released firmware V2.1 in late January 2018 to coincide with hardware product version 2 of both modules. The update introduces security-relevant hardening, server-certificate support for e-mail and DynDNS, and resolves several sporadic issues that had been observed in field installations running firmware V1.x and V2.0.x.

This reference covers the full scope of the V2.1 release, the prerequisites for flashing, the WBM update procedure, and the diagnostic checks that confirm a successful migration. Subsequent firmware revisions (V2.1.5, V2.1.7, and the discontinued V2.2.11) build on the same firmware base, so the V2.1 changes documented here remain the architectural baseline for the product line.

Security advisory: V2.1 contains hardening changes that improve robustness against potential attacks. Siemens strongly recommends that every installed CMR2020/CMR2040 running V1.x or V2.0.x be upgraded to V2.1 (or the latest available V2.1.x revision).

1. Affected Modules and Identification

Two distinct SKUs are covered by the V2.1 firmware image. Identification can be performed from the module label, the WBM Information page, or the LOGO! Soft Comfort topology scan.

Module Article Number Mobile Network Typical Use
LOGO! CMR2020 6GK7142-7BX00-0AX0 2G (GSM/GPRS) and LTE Cost-optimized remote alarm via SMS/e-mail
LOGO! CMR2040 6GK7142-7EX00-0AX0 LTE (4G) with fallback to 2G/3G High-availability telemetry and IPsec VPN

Locate the current firmware build on the WBM at:

System → Information → Firmware version

Or via the diagnostic page:

Diagnostics → Mobile data → Modem information

Hardware product version 2 modules are shipped from the factory with V2.1 pre-installed. Modules already deployed that ship with V1.x or V2.0.x can be updated in the field without hardware replacement.

2. Firmware Lifecycle and Subsequent Releases

V2.1 is the architectural baseline for the CMR2020/CMR2040 family. The V2.1 train has been revised several times since its initial release:

Release Status Notes
Firmware V2.1 Initial release (Jan 2018) Hardware product version 2 baseline
Firmware V2.1.5 Maintenance release Additional VPN and SMS bug fixes
Firmware V2.1.7 Released, free download Reference: Firmware update V2.1.7 for LOGO! CMR2020/CMR2040
Firmware V2.2.11 Discontinued 1 Oct 2023 Sales and delivery release closed per Siemens SiePortal product search

When planning a maintenance window, target the highest V2.1.x revision that is still available. The V2.2.x line has been retired and is no longer distributed.

3. Prerequisites

  1. Network reachability to the CMR module's Web Based Management (default https://192.168.0.10 for direct Ethernet connection, or the configured LAN address once integrated into the LOGO! 8 subnet).
  2. Valid admin credentials for the WBM. Default user: admin. If the password has been lost, a factory reset is required, which deletes all stored certificates and SMS data.
  3. Firmware file matching the module variant. Use only firmware images published in the Siemens Industry Online Support portal for the exact article number; cross-flashing between CMR2020 and CMR2040 is not supported.
  4. Stable power supply for the duration of the update. A brown-out or power cycle during the flash sequence can leave the module in a non-recoverable state requiring RMA.
  5. Backup of the configuration via System → Backup → Save configuration before the update.
  6. SIM card with PIN stored if mobile radio functions are required immediately after reboot.
Never power-cycle the module while the Activity LED is blinking in the firmware update pattern (rapid red/green alternation). Allow at least 90 seconds for the module to validate the new image, perform its first boot, and re-register on the mobile network.

4. Update Procedure via Web Based Management

All CMR2020 and CMR2040 modules that are already in service can be updated in the field. The WBM procedure applies to hardware versions 1 and 2 alike, provided the module is running V1.x or V2.0.x.

  1. Connect a PC to the Ethernet port of the CMR module. Use a static IP in the 192.168.0.0/24 range (for example 192.168.0.20) if the module is still at the default address.
  2. Open a browser and navigate to the WBM, accepting the self-signed certificate warning if the module has not yet been issued a trusted certificate.
  3. Log in with an administrator account.
  4. Navigate to System → Firmware update.
  5. Click Browse and select the firmware image (for example LOGO_CMR2020_V2.1.7.fw).
  6. Click Upload. The module will validate the image, write it to flash, and prepare to reboot.
  7. Confirm the prompt. The CMR restarts automatically; this takes approximately 60 to 90 seconds.
  8. Log in again and verify the firmware version on the Information page.
  9. Re-apply any custom configuration (SMS recipients, e-mail server, DynDNS provider, IPsec VPN) that was not included in the backup.

5. Functional Enhancements Introduced in V2.1

5.1 Server-Certificate Support for eMail and DynDNS

Prior to V2.1, the CMR2020/CMR2040 accepted only CA (Certificate Authority) certificates when validating e-mail and DynDNS server identities. This was sufficient for services using a publicly trusted CA, but prevented integration with private certificate authorities commonly used in plant networks.

V2.1 extends the certificate store so that individual server certificates (in addition to CA certificates) can be uploaded and pinned. This enables:

  • Use of self-signed SMTP/IMAP server certificates without installing a private CA chain.
  • Pinning to a specific DynDNS provider certificate, eliminating the dependency on the global trust store.
  • Stronger mutual authentication in environments where the server identity is fixed and known in advance.

Upload location: Security → Certificates → Server certificates. Accepted formats: .pem, .crt, .der.

5.2 SMS Burst Handling

Previous firmware revisions could drop or reorder messages when a burst of SMS notifications arrived within a short window (for example, several alarms triggered simultaneously after a power recovery). V2.1 processes every incoming SMS in the burst in arrival order, ensuring deterministic message handling. The maximum reliable burst rate depends on the mobile network and SIM card, but in field testing 20 messages in five seconds are now processed without loss.

6. Product Enhancements and Bug Fixes in V2.1

Area Symptom in V1.x / V2.0.x Resolution in V2.1
SIM card housekeeping Saved SMS remained on the SIM card after restart, eventually filling the limited SIM storage and blocking new messages. All stored SMS messages on the SIM card are deleted on every restart of the module.
Operating state changes Accidental clicks on the WBM Operating state page could trigger a restart, factory reset, or transition to the safe state, taking the remote site offline. A second confirmation click is now required for every operating-state change initiated from the WBM.
SMTP/IMAP with module certificate Sporadic connection failures to mail servers that required a client (module) certificate. The TLS handshake path for module-certificate-based SMTP/IMAP authentication has been corrected.
DynDNS provider Highly sporadic freezing of the CMR when transmitting the public IP address to the DynDNS provider. Freeze root cause addressed. See installation note in Section 7.
SMS/e-mail payload data type Counter and tag values that exceeded 16 bits (a Word) were truncated when sent over SMS or e-mail. A 32-bit DWord is now transmitted, restoring full range for analog values and counters.
Mobile network freeze Highly sporadic freeze of the CMR during send/receive over the mobile wireless network. Root cause addressed; module no longer hangs in the affected code path.
WBM input pages Layout and validation issues on several WBM input forms. Display and validation logic improved on multiple configuration pages.
Mobile data counters in LTE The sent/received mobile-data counters were stuck or displayed zero while the module was operating on an LTE cell. Counters now report correct values and reset correctly in LTE mode.

7. Installation Notes and Configuration Migration

DynDNS providers and IP transmission: When the DynDNS provider transmits the IP address, configure the provider to send a fully qualified hostname rather than a numeric IP, and confirm the TTL value on the provider side. Although V2.1 addresses the freeze, certain low-end DynDNS providers have been observed to return malformed responses that still cause timeouts. Increase the retry interval in System → DynDNS → Retry interval to at least 300 s to reduce the probability of a stall.

Configuration parameters from V1.x and V2.0.x are preserved across the update, with the following exceptions:

  • Custom server certificates must be re-uploaded. The V2.1 image initializes the certificate store with defaults that do not include any previously loaded server certificates.
  • If a module certificate (client certificate) was used, verify that the certificate chain is still valid and that the CA has not been rotated during the update window.
  • All saved SMS messages on the SIM card are cleared by design after the first restart on V2.1. If a forensic record of historical alarms is required, retrieve SMS via the LOGO! Soft Comfort trace or the WBM Diagnostics → SMS buffer before performing the update.

8. Verification Procedure

After the firmware update completes, perform the following checks before returning the module to service:

  1. Firmware version: System → Information → Firmware version should report the new V2.1.x build.
  2. Mobile registration: Diagnostics → Mobile data → Signal quality should show a non-zero signal level and a registered operator.
  3. Mobile data counters (LTE-capable modules): Trigger a small data exchange and confirm the sent/received counters increment.
  4. SMS round-trip: Send a test SMS to a known recipient and confirm delivery; trigger an alarm to the CMR and confirm the module processes the incoming message.
  5. e-mail delivery: Send a test e-mail via Diagnostics → e-mail test. If a server certificate is configured, confirm the TLS handshake succeeds against the pinned certificate.
  6. DynDNS update: Force a DynDNS update from System → DynDNS → Update now and confirm the IP address is reported correctly on the provider's portal.
  7. Operating state protection: Verify that clicking Restart in the WBM requires a second confirmation click. This confirms the V2.1 guard is active.

9. Troubleshooting Matrix

Observed Issue Likely Cause Resolution
Module unreachable after update IP address or VLAN changed during the boot phase Check Ethernet link, ping the default address 192.168.0.10, scan the subnet if the address was changed pre-update.
Firmware upload rejected Image does not match the article number (CMR2020 vs CMR2040) Re-download the correct image from the Siemens support entry.
SMS messages lost SIM card full of pre-existing messages on legacy firmware V2.1 clears stored SMS on restart. Power-cycle once after the update to complete the cleanup.
e-mail TLS handshake fails after V2.1 Server certificate was previously implicitly trusted via CA; V2.1 requires explicit pinning Upload the server certificate in Security → Certificates → Server certificates, or restore the CA chain.
DynDNS still freezes occasionally Provider returns malformed responses Increase the retry interval; consider switching to a provider that uses standard HTTP updates.
Counter values truncated over SMS Module running pre-V2.1 firmware Update to V2.1.7 to obtain the DWord transmission fix.
Mobile data counter stuck at 0 in LTE Pre-V2.1 firmware bug Update to V2.1; confirm reset works on Diagnostics → Mobile data → Reset counter.

10. Rollback Considerations

Siemens does not publish a downgrade path from V2.1 to earlier firmware builds. If a field deployment must revert to a previous revision, the only supported procedure is a return-to-factory (via System → Reset → Factory settings) followed by uploading the older image. This clears all configuration, certificates, and SMS history, and is therefore a maintenance event that must be scheduled.

Configuration export: Always export the WBM configuration (System → Backup → Export) before initiating a factory reset. The exported archive contains SMS routing rules, e-mail server profiles, DynDNS credentials, IPsec VPN parameters, and certificate references. Re-import these after the rollback to restore the original deployment state.

11. Field-Commissioning Checklist

For new deployments using hardware product version 2 modules (factory-shipped with V2.1), the commissioning sequence is:

  1. Insert SIM card and connect the antenna before applying power.
  2. Connect Ethernet, log in to the WBM, change the default admin password, and assign a static LAN address that matches the LOGO! 8 subnet.
  3. Configure the SMS and e-mail recipients in System → Notifications.
  4. If using a private CA, upload the CA and any required server certificates.
  5. If using VPN (CMR2040), configure IPsec profiles in Security → VPN and import the remote peer certificate.
  6. Trigger a test alarm from LOGO! Soft Comfort and confirm the notification chain end to end.
  7. Record the firmware version, signal quality, and SIM card ICCID in the commissioning report.

12. FAQ

What is the latest available firmware for the LOGO! CMR2020 and CMR2040?

The latest actively distributed line is firmware V2.1.7, available on the Siemens Industry Online Support portal. The newer V2.2.11 line was discontinued on 1 October 2023 and is no longer available for new deployments.

Can I update the CMR2020 firmware without sending the module back to Siemens?

Yes. Modules already in service running V1.x or V2.0.x can be updated in the field via the Web Based Management (WBM) at System → Firmware update. Only the correct firmware image for the article number must be used.

Does firmware V2.1 reset my configuration or delete SMS history?

The V2.1 update preserves WBM configuration, but it intentionally deletes all SMS messages stored on the SIM card during the first restart. Re-apply any custom server certificates and module certificates after the update, as the certificate store is re-initialized.

What security improvements does V2.1 introduce?

V2.1 adds hardening against potential attacks, enables pinning of individual server certificates for e-mail and DynDNS in addition to CA certificates, and requires a second confirmation click for any change of operating state initiated from the WBM. This prevents accidental restarts or factory resets.

Is the DWord fix in V2.1 important for analog value reporting?

Yes. Pre-V2.1 firmware incorrectly sent a 16-bit Word for tag values, truncating any value above 32767. V2.1 transmits a 32-bit DWord, which is required for correct reporting of analog process values, energy counters, and elapsed-time tags sent over SMS or e-mail.

Back to blog