Executive brief
The Hirschmann HiOS Switch Platform, used for industrial networking, contains a vulnerability in its web management interface. An attacker can remotely force the switch to reboot by sending a specifically crafted web request. This results in a denial-of-service condition, disrupting network connectivity and potentially impacting industrial operations that rely on the switch.
Technical details
A denial-of-service (DoS) vulnerability exists in the web interface of Hirschmann HiOS Switch Platform due to missing authentication for a critical function (CWE-306). A remote, unauthenticated attacker can exploit this by sending a crafted HTTP GET request to a specific endpoint. Successful exploitation triggers an uncontrolled reboot of the device, leading to service unavailability. The vulnerability affects versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00; it is addressed in versions 09.4.05 and 10.3.01.
Affected products
- Hirschmann HiOS Switch Platform 09.1.00 through 09.4.04, 10.0.00 through 10.3.00
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory