CVE-2026-89025: Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request

Published Sep 15, 2026
·
Updated

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

Affected Software

1 affected component
Hirschmann HiOS Switch Platform<07.1.12, <08.7.10, <09.0.13, <09.3.03, <10.3.08, <10.5.00

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 07.1.12
  2. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 08.7.10
  3. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 09.0.13
  4. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 09.3.03
  5. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 10.3.08
  6. Upgrade

    Upgrade Hirschmann HiOS Switch Platform to a version that resolves this vulnerability.

    Fixed in 10.5.00

Event History

Sep 15, 2026
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices are exposed to exploitation?

Hirschmann HiOS Switch Platform devices are exposed if their integrated web server can be reached by a remote attacker over HTTP or HTTPS. No authentication or user interaction is required.

2

What is required to trigger the denial of service?

An attacker only needs to send a specially crafted HTTP(S) request to a specific endpoint. The malformed content is processed incorrectly and causes an unintended device reboot.

3

Which software versions address the issue?

The issue has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203