---
id: CVE-2018-25236
title: >-
  Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX,
  GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the
  HTTP(S) management module that allows unauthenticated remote attackers to gain
  administ…
summary: >-
  Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX,
  GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the
  HTTP(S) management module that allows unauthenticated remote attackers to gain
  administ…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
published: '2026-04-03'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25236'
references:
  - url: >-
      https://assets.belden.com/m/52ecadbb5f1b0e04/original/Security-Bulletin-Web-Server-Authentication-Bypass-HiOS-HiSecOS-Hirschmann-BSECV-2018-05.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hirschmann-hios-hisecos-authentication-bypass-via-http-management
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00502
epssPercentile: 0.41812
ingestedAt: '2026-07-21T16:51:40.874Z'
---

## Overview

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
