Description
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via device reboot
Action: Immediate Patch
AI Analysis

Impact

The flaw in the Hirschmann HiOS Switch Platform web server is a missing validation of HTTP(S) content, identified as CWE‑755. A remote, unauthenticated attacker can send a specially crafted request to a particular endpoint. The server parses the malformed payload incorrectly, causing the device to reboot unexpectedly. This reboot disables network connectivity for a short time, producing a temporary denial‑of‑service condition.

Affected Systems

The vulnerability affects Hirschmann HiOS Switch Platform devices sold by Belden. Firmware releases 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00 include the fix; earlier firmware versions remain vulnerable.

Risk and Exploitability

With a CVSS score of 8.7, the issue is classified as high severity, indicating that any exposed device can be disrupted without authentication. The EPSS score is 0.00423, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, yet its straightforward remote exploitation path and the ability to interrupt network services place it at significant risk for exposed switches. An attacker only needs to issue a malformed HTTP request to trigger a reboot, so hardening network perimeter controls or blocking the affected web endpoint remains critical until a patch can be applied.

Generated by OpenCVE AI on September 17, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade firmware to a release that includes the fix (for example 07.1.12 or newer).
  • If an upgrade is not immediately possible, block or restrict access to the web interface endpoint that receives the malformed request using firewall or access‑control rules.
  • Enable logging and alerting for unexpected reboot events so that repeated malformed requests can be detected and investigated.

Generated by OpenCVE AI on September 17, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Belden hirschmann Hios
CPEs cpe:2.3:o:belden:hirschmann_hios:*:*:*:*:*:*:*:*
cpe:2.3:o:belden:hirschmann_hios:10.4.00:*:*:*:*:*:*:*
cpe:2.3:o:belden:hirschmann_hios:10.5.00:*:*:*:*:*:*:*
Vendors & Products Belden hirschmann Hios

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Belden
Belden hirschmann Hios Switch Platform
Vendors & Products Belden
Belden hirschmann Hios Switch Platform

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Title Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Belden Hirschmann Hios Hirschmann Hios Switch Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:50.914Z

Reserved: 2026-09-10T16:23:54.471Z

Link: CVE-2026-89025

cve-icon Vulnrichment

Updated: 2026-09-15T14:48:45.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:26.720

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-89025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:30:06Z

Weaknesses
  • CWE-755

    Improper Handling of Exceptional Conditions