ZeroHour

CVE-2026-89025

moderate

Unauthenticated HTTP DoS Reboot in Hirschmann HiOS Switches

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Hirschmann HiOS Switch Platform devices suffer from a denial-of-service vulnerability in the integrated web server caused by missing validation of HTTP(S) content (CWE-755, improper handling of exceptional conditions). A remote, unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, forcing the device to perform an unintended reboot and causing a temporary denial of service. The flaw carries a CVSS 4.0 base score of 8.7 (high) because it is network-reachable with no privileges or user interaction required, though it affects only availability. It impacts managed industrial Ethernet switches deployed in OT/ICS environments such as factories, energy networks, and transportation systems, where even a temporary switch reboot can disrupt production. No public proof-of-concept exists and the vulnerability is not in the CISA KEV catalog, so exploitation is presumed possible but not observed.

What to do: Upgrade to the fixed firmware for your release train: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00. Until patched, restrict HTTP(S) management access to trusted management VLANs or VPNs, and disable the web-based management interface entirely if it is not required. Monitor devices for unexpected reboots, which are the telltale symptom of this vulnerability being triggered.

Affected
Hirschmann (Belden) HiOS Switch PlatformAll HiOS firmware prior to the fixed releases in each train: prior to 07.1.12, prior to 08.7.10, prior to 09.0.13, prior to 09.3.03, prior to 10.3.08, and prior
Estimated exposure
moderateLow thousands of internet-exposed devices (management interfaces), out of a global installed base plausibly in the hundreds of thousands — Hirschmann is a leading industrial Ethernet switch vendor with a large OT installed base, but public scan services typically show only low thousands of Hirschmann web interfaces reachable from the internet since these devices are normally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

Weakness
CWE-755
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.