CVE-2026-89025: Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 07.1.12 - Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 08.7.10 - Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 09.0.13 - Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 09.3.03 - Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 10.3.08 - Upgrade
Upgrade
Hirschmann HiOS Switch Platformto a version that resolves this vulnerability.Fixed in 10.5.00
Event History
Frequently Asked Questions
Which devices are exposed to exploitation?
Hirschmann HiOS Switch Platform devices are exposed if their integrated web server can be reached by a remote attacker over HTTP or HTTPS. No authentication or user interaction is required.
What is required to trigger the denial of service?
An attacker only needs to send a specially crafted HTTP(S) request to a specific endpoint. The malformed content is processed incorrectly and causes an unintended device reboot.
Which software versions address the issue?
The issue has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.