---
id: CVE-2026-89025
title: >-
  Hirschmann HiOS Switch Platform devices contain a denial-of-service
  vulnerability in the integrated web server due to missing validation of
  HTTP(S) content
summary: >-
  Hirschmann HiOS Switch Platform devices contain a denial-of-service
  vulnerability in the integrated web server due to missing validation of
  HTTP(S) content. A remote unauthenticated attacker can send a specially
  crafted HTTP(S) request t…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-755
vendor: Belden
product: Hirschmann HiOS Switch Platform
affected:
  - hirschmann_hios_switch_platform >= 07.0.0 <= 07.1.11
  - hirschmann_hios_switch_platform >= 08.0.0 <= 08.7.09
  - hirschmann_hios_switch_platform >= 09.0.00 <= 09.0.12
  - hirschmann_hios_switch_platform >= 09.3.00 <= 09.3.02
  - hirschmann_hios_switch_platform >= 10.0.0 <= 10.3.07
  - hirschmann_hios_switch_platform 10.4.00
  - hirschmann_hios_switch_platform 10.5.00
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:44:42.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89025'
references:
  - url: >-
      https://assets.belden.com/asset/2ba884e3-c0c9-40f6-aa22-a9e852b20af4/PSIRT-6_HTTPS_Vulnerability_HiOS.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hirschmann-hios-switch-platform-dos-via-malformed-http-request
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.0077
epssPercentile: 0.53798
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T14:48:42.364163Z'
ingestedAt: '2026-09-15T14:38:16.203Z'
---

## Overview

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
