Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform
Hirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.
CVE search metadata
CVE search record: CVE-2026-89025. Severity: high. CVSS: 7.5. KEV: no. Product: HiOS Switch Platform (< 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, 10.5.00). Brief: Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform. Brief link: https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in their integrated web server. The flaw arises from missing validation of HTTP(S) content processed by the device. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP(S) request to a specific endpoint, which triggers an unintended reboot of the switch. This results in a temporary denial-of-service condition for the device and any traffic passing through it. The vulnerability is tracked as CVE-2026-89025. Hirschmann has released security updates to address this issue, and administrators are advised to verify firmware versions against the patched releases.
Impact
Successful exploitation results in an immediate and temporary denial-of-service of Hirschmann network switches, which can disrupt critical infrastructure communication. Affected sectors include industrial control systems and enterprise network environments where HiOS-based switches are deployed to manage traffic. Impact is limited to device availability due to forced reboots.
Recommendation
- Upgrade affected Hirschmann HiOS firmware to the patched versions: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00.
- Restrict access to the management web interface of network switches to trusted management subnets or via out-of-band management networks to minimize the attack surface for CVE-2026-89025.
Mitigations
Upgrade HiOS firmware to version 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00
CVE-2026-89025