CVE-2018-25237: Hirschmann HiSecOS Buffer Overflow via HTTPS Login

Published Apr 3, 2026
·
Updated

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

Affected Software

1 affected component
Hirschmann HiSecOS<05.3.03

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Hirschmann HiSecOS to a version that resolves this vulnerability.

    Fixed in 05.3.03
  2. Compensating control

    If upgrading is not immediately possible, mitigate exposure by preventing remote access to the HTTPS login interface where RADIUS authentication is enabled (e.g., restrict management/HTTPS login access via network controls such as firewall/ACL to trusted sources only).

Event History

Apr 3, 2026
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2018-25237?

CVE-2018-25237 is classified as a high severity vulnerability due to its potential to allow remote code execution.

2

How do I fix CVE-2018-25237?

To fix CVE-2018-25237, upgrade your Hirschmann HiSecOS devices to version 05.3.03 or later.

3

What devices are affected by CVE-2018-25237?

CVE-2018-25237 affects Hirschmann HiSecOS devices running versions prior to 05.3.03.

4

What type of attack can exploit CVE-2018-25237?

CVE-2018-25237 can be exploited through a buffer overflow attack via the HTTPS login interface when RADIUS authentication is enabled.

5

Can CVE-2018-25237 lead to device crashes?

Yes, CVE-2018-25237 allows attackers to potentially crash the device as well as execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203