Executive brief
Hirschmann HiOS switches are managed network devices that route traffic in industrial and enterprise environments. The integrated web server contains an input validation flaw that allows remote attackers to crash the device with a malformed HTTP request, causing temporary network outage until the device reboots and comes back online.
Technical details
The vulnerability is an improper handling of exceptional conditions (CWE-755) in the HiOS web server that fails to validate HTTP(S) request content. A remote, unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint, which is processed incorrectly by the web server, triggering an unintended device reboot. The attack requires only network reachability to the web interface (no authentication or user interaction needed). The impact is temporary denial of service; the device recovers after reboot. Patches are available in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.
Affected products
- Hirschmann HiOS Switch Platform 07.0.0 through 07.1.11, 08.0.0 through 08.7.09, 09.0.00 through 09.0.12, 09.3.00 through 09.3.02, 10.0.0 through 10.3.07
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Patches released in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00