Sceawere
Vulnerability Detail
CVE-2026-89025UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Hirschmann HiOS DoS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Belden
- Product
- Hirschmann HiOS Switch Platform
- Attack Type
- Improper Handling of Exceptional Conditions
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-15T15:17:26.720Z",
"pubdate": "2026-09-15T15:17:26.720Z",
"executiveSummary": "This vulnerability concerns a Denial-of-Service (DoS) condition affecting the integrated web server within Hirschmann HiOS Switch Platform devices.\nThe flaw stems from insufficient validation of incoming HTTP(S) content, which allows remote, unauthenticated attackers to trigger an unintended device reboot.\nThe impact of successful exploitation is a temporary denial-of-service, rendering the switch unreachable and potentially disrupting critical network operations.\nThe vulnerability requires no prior authentication or administrative privileges, making it accessible to any actor with network visibility to the device's web management interface.\nRisk implications are high for industrial control and enterprise environments where constant availability is required, as the exploit forces an immediate system restart.\nAffected products include Hirschmann HiOS Switch Platform devices running versions prior to 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.",
"technicalDetails": "The vulnerability resides within the request parsing logic of the embedded HTTP(S) server utilized by the Hirschmann HiOS firmware. The root cause is a deficiency in input validation mechanisms, specifically regarding the processing of specific, malformed HTTP(S) payloads.\nWhen the web server receives a specially crafted request directed at a specific endpoint, the lack of rigorous input verification leads to an improper state transition or memory handling error during the parsing phase. This failure triggers an exception or unhandled state within the web server process that forces the device's watchdog timer or operating system to initiate a hard reboot to recover the platform.\nExploitation does not require authentication, as the vulnerable endpoint is accessible prior to the establishment of an authorized session. An attacker transmits a maliciously crafted HTTP(S) request to the target device via standard networking protocols. Once the request reaches the vulnerable HTTP(S) parsing component, the system fails to safely sanitize the input. Because the web server is deeply integrated into the management stack of the HiOS platform, the resulting error causes a catastrophic failure of the control plane process, manifesting as a reboot of the device.\nThe attack flow follows a direct vector: 1) The attacker identifies the target's web interface, 2) The attacker crafts a request payload designed to exploit the parsing flaw, 3) The attacker submits the payload to the targeted endpoint over HTTP or HTTPS, 4) The device's web server process encounters an unhandled exception upon parsing the malicious input, 5) The firmware triggers a recovery operation, resulting in an immediate and unintended device reboot.\nThe post-exploitation impact is limited to a transient denial-of-service. While the device reboots, it is unable to forward traffic or provide management functions, causing a disruption in network communications. This vulnerability can be exploited repeatedly, allowing an attacker to persist in a denial-of-service state by continuously sending the malformed request, provided they maintain network access to the management interface.\nThe vulnerability affects versions prior to 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00. Exposure is strictly network-based; any interface (LAN/WAN) providing access to the switch's web management service is a potential point of attack."
}