CVE-2026-89025
Received
Received - Intake
Denial-of-Service in Hirschmann HiOS Switch Platform
Vulnerability report for CVE-2026-89025, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-15
Last updated on: 2026-09-15
Assigner: VulnCheck
Description
Description
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hirschmann | hios_switch_platform | From 07.0.0 (inc) to 10.3.08 (exc) |
| hirschmann | hios_switch_platform | 07.1.12 |
| hirschmann | hios_switch_platform | 08.7.10 |
| hirschmann | hios_switch_platform | 09.0.13 |
| hirschmann | hios_switch_platform | 09.3.03 |
| hirschmann | hios_switch_platform | 10.3.08 |
| hirschmann | hios_switch_platform | 10.5.00 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-755 | The product does not handle or incorrectly handles an exceptional condition. |