Junglewise Threat Intelligence

CVE-2025-15620: Hirschmann HiOS Switch Platform denial of service in web interface

CVE-2025-15620 · Severity: high · CVSS 8.6 · Published 2026-04-02

Vendors: Hirschmann.

Executive brief

The Hirschmann HiOS Switch Platform, used for industrial networking, contains a vulnerability in its web management interface. An attacker can remotely force the switch to reboot by sending a specifically crafted web request. This results in a denial-of-service condition, disrupting network connectivity and potentially impacting industrial operations that rely on the switch.

Technical details

A denial-of-service (DoS) vulnerability exists in the web interface of Hirschmann HiOS Switch Platform due to missing authentication for a critical function (CWE-306). A remote, unauthenticated attacker can exploit this by sending a crafted HTTP GET request to a specific endpoint. Successful exploitation triggers an uncontrolled reboot of the device, leading to service unavailability. The vulnerability affects versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00; it is addressed in versions 09.4.05 and 10.3.01.

Affected products

  • Hirschmann HiOS Switch Platform 09.1.00 through 09.4.04, 10.0.00 through 10.3.00

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats