Description
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Published: 2026-09-15
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via device reboot
Action: Immediate Patch
AI Analysis

Impact

The flaw in the Hirschmann HiOS Switch Platform web server is a missing validation of HTTP(S) content, identified as CWE‑755. A remote, unauthenticated attacker can send a specially crafted request to a particular endpoint. The server parses the malformed payload incorrectly, causing the device to reboot unexpectedly. This reboot disables network connectivity for a short time, producing a temporary denial‑of‑service condition.

Affected Systems

The vulnerability affects Hirschmann HiOS Switch Platform devices sold by Belden. Firmware releases up to (but not including) 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00 contain the fix; older firmware versions are considered vulnerable.

Risk and Exploitability

With a CVSS score of 8.7, the issue is classified as high severity, indicating that any exposed device can be disrupted without authentication. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet its straightforward remote exploitation path and the ability to interrupt network services place it at significant risk for exposed switches. An attacker only needs to issue a malformed HTTP request to trigger a reboot, so hardening network perimeter controls or blocking the affected web endpoint remains critical until a patch can be applied.

Generated by OpenCVE AI on September 16, 2026 at 06:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade firmware to a release that includes the fix (for example 07.1.12 or newer).
  • If an upgrade is not immediately possible, block or restrict access to the web interface endpoint that receives the malformed request using firewall or access‑control rules.
  • Enable logging and alerting for unexpected reboot events so that repeated malformed requests can be detected and investigated.

Generated by OpenCVE AI on September 16, 2026 at 06:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Belden
Belden hirschmann Hios Switch Platform
Vendors & Products Belden
Belden hirschmann Hios Switch Platform

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Title Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Belden Hirschmann Hios Switch Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T14:48:49.074Z

Reserved: 2026-09-10T16:23:54.471Z

Link: CVE-2026-89025

cve-icon Vulnrichment

Updated: 2026-09-15T14:48:45.823Z

cve-icon NVD

Status : Received

Published: 2026-09-15T15:17:26.720

Modified: 2026-09-15T15:17:26.720

Link: CVE-2026-89025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:15:07Z

Weaknesses
  • CWE-755

    Improper Handling of Exceptional Conditions