Executive brief
Hirschmann HiEOS devices, which are industrial networking operating systems used in critical infrastructure, contain a security flaw in their web management interface. An attacker can bypass login requirements to gain full administrative control over the device. This allows them to steal configuration files, disrupt network traffic, or install malicious firmware, potentially leading to significant operational downtime or data theft.
Technical details
An authentication bypass vulnerability (CWE-287) exists in the HTTP(S) management module of Hirschmann HiEOS. The root cause is improper authentication handling when processing specially crafted HTTP(S) requests. A remote, unauthenticated attacker can exploit this flaw over the network to obtain elevated administrative privileges. Successful exploitation enables unauthorized actions such as downloading or uploading device configurations and performing firmware modifications. The vulnerability is addressed in HiEOS version 01.1.00.
Affected products
- Hirschmann (Belden) HiEOS LRS11 prior to 01.1.00
Timeline
- 2026-04-02: advisory: Initial advisory published by Belden/VulnCheck
- 2026-04-02: disclosed