CVE-2026-89025

Summary

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

Affected Software

VendorProductVersion RangeStatus
BeldenHirschmann HiOS Switch Platform07.0.0 <= 07.1.11affected
BeldenHirschmann HiOS Switch Platform07.1.12unaffected
BeldenHirschmann HiOS Switch Platform08.0.0 <= 08.7.09affected
BeldenHirschmann HiOS Switch Platform08.7.10unaffected
BeldenHirschmann HiOS Switch Platform09.0.00 <= 09.0.12affected
BeldenHirschmann HiOS Switch Platform09.0.13unaffected
BeldenHirschmann HiOS Switch Platform09.3.00 <= 09.3.02affected
BeldenHirschmann HiOS Switch Platform09.3.03unaffected
BeldenHirschmann HiOS Switch Platform10.0.0 <= 10.3.07affected
BeldenHirschmann HiOS Switch Platform10.3.08unaffected
BeldenHirschmann HiOS Switch Platform10.4.00affected
BeldenHirschmann HiOS Switch Platform10.5.00affected

Weaknesses

  • CWE-755: Improper Handling of Exceptional Conditions

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References