CVE-2026-89025
moderateUnauthenticated HTTP DoS Reboot in Hirschmann HiOS Switches
Hirschmann HiOS Switch Platform devices suffer from a denial-of-service vulnerability in the integrated web server caused by missing validation of HTTP(S) content (CWE-755, improper handling of exceptional conditions). A remote, unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, forcing the device to perform an unintended reboot and causing a temporary denial of service. The flaw carries a CVSS 4.0 base score of 8.7 (high) because it is network-reachable with no privileges or user interaction required, though it affects only availability. It impacts managed industrial Ethernet switches deployed in OT/ICS environments such as factories, energy networks, and transportation systems, where even a temporary switch reboot can disrupt production. No public proof-of-concept exists and the vulnerability is not in the CISA KEV catalog, so exploitation is presumed possible but not observed.
What to do: Upgrade to the fixed firmware for your release train: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00. Until patched, restrict HTTP(S) management access to trusted management VLANs or VPNs, and disable the web-based management interface entirely if it is not required. Monitor devices for unexpected reboots, which are the telltale symptom of this vulnerability being triggered.
| Hirschmann (Belden) HiOS Switch Platform | All HiOS firmware prior to the fixed releases in each train: prior to 07.1.12, prior to 08.7.10, prior to 09.0.13, prior to 09.3.03, prior to 10.3.08, and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
- Weakness
- CWE-755
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.