CVE-2026-89025
Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
| CWE | CWE-755 |
| Vendor | belden |
| Product | hirschmann hios switch platform |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for belden hirschmann hios switch platform
Be the first to know when new high vulnerabilities affecting belden hirschmann hios switch platform are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Belden / Hirschmann HiOS Switch Platform
07.0.0 โค 07.1.11 08.0.0 โค 08.7.09 09.0.00 โค 09.0.12 09.3.00 โค 09.3.02 10.0.0 โค 10.3.07 10.4.00 10.5.00