CVE-2026-89025
Received Received - Intake

Denial-of-Service in Hirschmann HiOS Switch Platform

Vulnerability report for CVE-2026-89025, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
hirschmann hios_switch_platform From 07.0.0 (inc) to 10.3.08 (exc)
hirschmann hios_switch_platform 07.1.12
hirschmann hios_switch_platform 08.7.10
hirschmann hios_switch_platform 09.0.13
hirschmann hios_switch_platform 09.3.03
hirschmann hios_switch_platform 10.3.08
hirschmann hios_switch_platform 10.5.00

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in Hirschmann HiOS Switch Platform devices caused by missing validation of HTTP(S) content in the integrated web server. A remote unauthenticated attacker can exploit it by sending a specially crafted HTTP(S) request to a specific endpoint, triggering an unintended reboot and temporary loss of availability.

Detection Guidance

Monitor network traffic for unusual HTTP(S) requests targeting HiOS switch endpoints. Check device logs for unexpected reboots or error messages related to web server processing. Use network scanning tools to identify vulnerable versions of Hirschmann HiOS Switch Platform.

Impact Analysis

The vulnerability allows attackers to cause temporary network outages by rebooting affected switches remotely without authentication. This disrupts network services, leading to downtime for connected systems and potential loss of critical operations relying on these devices.

Compliance Impact

This vulnerability causes temporary denial-of-service conditions by rebooting affected devices, which may disrupt network availability. For GDPR, this could impact data processing operations requiring continuous availability. For HIPAA, it may affect systems handling protected health information by causing service interruptions.

Mitigation Strategies

Upgrade affected HiOS Switch Platform devices to patched versions (07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00). Disable unnecessary web server access if possible. Implement network segmentation to limit exposure of vulnerable devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89025. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart