CVE-2025-15620
Analyzed
Analyzed - Analysis Complete
Denial-of-Service in HiOS Switch Web Interface Causes Reboot
Publication date: 2026-04-02
Last updated on: 2026-06-05
Assigner: VulnCheck
Description
Description
HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| belden | hios_switch | From 09.1.00 (inc) to 09.4.05 (exc) |
| belden | hios_switch | From 10.0.00 (inc) to 10.3.01 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |