๐Ÿ” CVE Alert

CVE-2026-89025

HIGH 7.5

Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

CWE CWE-755
Vendor belden
Product hirschmann hios switch platform
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for belden hirschmann hios switch platform

Be the first to know when new high vulnerabilities affecting belden hirschmann hios switch platform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Belden / Hirschmann HiOS Switch Platform
07.0.0 โ‰ค 07.1.11 08.0.0 โ‰ค 08.7.09 09.0.00 โ‰ค 09.0.12 09.3.00 โ‰ค 09.3.02 10.0.0 โ‰ค 10.3.07 10.4.00 10.5.00

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
assets.belden.com: https://assets.belden.com/asset/2ba884e3-c0c9-40f6-aa22-a9e852b20af4/PSIRT-6_HTTPS_Vulnerability_HiOS.pdf vulncheck.com: https://www.vulncheck.com/advisories/hirschmann-hios-switch-platform-dos-via-malformed-http-request