{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hios-switch-platform--07.1.12-08.7.10-09.0.13-09.3.03-10.3.08-10.5.00/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hirschmann:hios_switch_platform:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89025"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HiOS Switch Platform (\u003c 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, 10.5.00)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Hirschmann"],"content_html":"\u003cp\u003eHirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in their integrated web server. The flaw arises from missing validation of HTTP(S) content processed by the device. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP(S) request to a specific endpoint, which triggers an unintended reboot of the switch. This results in a temporary denial-of-service condition for the device and any traffic passing through it. The vulnerability is tracked as CVE-2026-89025. Hirschmann has released security updates to address this issue, and administrators are advised to verify firmware versions against the patched releases.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate and temporary denial-of-service of Hirschmann network switches, which can disrupt critical infrastructure communication. Affected sectors include industrial control systems and enterprise network environments where HiOS-based switches are deployed to manage traffic. Impact is limited to device availability due to forced reboots.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade affected Hirschmann HiOS firmware to the patched versions: 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, or 10.5.00.\u003c/li\u003e\n\u003cli\u003eRestrict access to the management web interface of network switches to trusted management subnets or via out-of-band management networks to minimize the attack surface for CVE-2026-89025.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T15:41:03Z","date_published":"2026-09-15T15:41:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/","summary":"Hirschmann HiOS Switch Platform devices are susceptible to a remote unauthenticated denial-of-service vulnerability due to improper input validation in the integrated web server.","title":"Denial-of-Service Vulnerability in Hirschmann HiOS Switch Platform","url":"https://feed.craftedsignal.io/briefs/2026-09-hirschmann-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - HiOS Switch Platform (\u003c 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, 10.5.00)","version":"https://jsonfeed.org/version/1.1"}