Denial of Service Vulnerability in Hirschmann HiOS Switch Platform Devices
CVE-2026-89025

8.7HIGH

Key Information:

Vendor

Belden

Vendor
CVE Published:
15 September 2026

What is CVE-2026-89025?

The Hirschmann HiOS Switch Platform devices are susceptible to a denial-of-service issue stemming from inadequate validation of HTTP(S) content within their integrated web server. A remote, unauthenticated attacker can exploit this flaw by sending a specifically crafted HTTP(S) request to a designated endpoint, leading to improper processing that may trigger unintended reboots of the affected device. This results in a temporary denial-of-service state, impacting network availability.

Affected Version(s)

Hirschmann HiOS Switch Platform 07.0.0 <= 07.1.11

Hirschmann HiOS Switch Platform 08.0.0 <= 08.7.09

Hirschmann HiOS Switch Platform 09.0.00 <= 09.0.12

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.