Executive brief
A vulnerability in Hirschmann industrial networking devices can allow an attacker to remotely crash the hardware, leading to a complete loss of network connectivity. These devices are typically used in industrial environments to manage secure data traffic; an exploit could disrupt manufacturing operations or critical infrastructure monitoring. The issue occurs when the device attempts to establish a secure connection, allowing an attacker to force a system failure without needing any login credentials.
Technical details
The vulnerability manifests as a denial-of-service (DoS) condition during the TLS handshake process or via the HiLCOS web interface. In EagleSDV firmware, the crash is triggered by exploiting protocol downgrades to TLS 1.0 or 1.1 during session establishment. In other HiLCOS-based products (such as the BAT series), the issue is identified as a heap-based buffer overflow (CWE-122) within the web interface, particularly when the 'Public Spot' functionality is enabled. An unauthenticated remote attacker can trigger these crashes by sending specially crafted network requests, resulting in a device reboot or service interruption. The vulnerability is addressed in EagleSDV firmware version 05.4.02 and HiLCOS version 10.34.6464.
Affected products
- Hirschmann (Belden) EagleSDV prior to 05.4.02
- Hirschmann (Belden) HiLCOS (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) 10.34.6313 to 10.34.6464
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory