7.5

CVE-2026-89025

Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBelden
≫
Produkt Hirschmann HiOS Switch Platform
Default Statusunaffected
Version <= 07.1.11
Version 07.0.0
Status affected
Version 07.1.12
Status unaffected
Version <= 08.7.09
Version 08.0.0
Status affected
Version 08.7.10
Status unaffected
Version <= 09.0.12
Version 09.0.00
Status affected
Version 09.0.13
Status unaffected
Version <= 09.3.02
Version 09.3.00
Status affected
Version 09.3.03
Status unaffected
Version <= 10.3.07
Version 10.0.0
Status affected
Version 10.3.08
Status unaffected
Version 10.4.00
Status affected
Version 10.5.00
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.36
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
disclosure@vulncheck.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

https://assets.belden.com/asset/2ba884e3-c0c9-40f6-aa22-a9e852b20af4/PSIRT-6_HTTPS_Vulnerability_HiOS.pdf
https://www.vulncheck.com/advisories/hirschmann-hios-switch-platform-dos-via-malformed-http-request