Skip to content
Threat Feed
low advisory

Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform

Hirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.

CVE search metadata

CVE search record: CVE-2026-89025. Severity: high. CVSS: 7.5. KEV: no. Product: HiOS Switch Platform (< 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, 10.5.00). Brief: Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in their integrated web server. The flaw arises from missing validation of HTTP(S) content processed by the device. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP(S) request to a specific endpoint, which triggers an unintended reboot of the switch. This results in a temporary denial-of-service condition for the device and any traffic passing through it. The vulnerability is tracked as CVE-2026-89025. Hirschmann has released security updates to address this issue, and administrators are advised to verify firmware versions against the patched releases.

Impact

Successful exploitation results in an immediate and temporary denial-of-service of Hirschmann network switches, which can disrupt critical infrastructure communication. Affected sectors include industrial control systems and enterprise network environments where HiOS-based switches are deployed to manage traffic. Impact is limited to device availability due to forced reboots.

Recommendation

  • Upgrade affected Hirschmann HiOS firmware to the patched versions: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00.
  • Restrict access to the management web interface of network switches to trusted management subnets or via out-of-band management networks to minimize the attack surface for CVE-2026-89025.

Mitigations

Upgrade HiOS firmware to version 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00

immediate Network Security

CVE-2026-89025