← All Advisories

CVE-2025-15620

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2025-15620

Key Details

CVECVE-2025-15620
CVSS Score / Version8.6 (High) / CVSS v3.1
Updated2026-07-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsBelden hios_switch and Belden Hirschmann HiOS Switch Platform
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Beldenhios_switch
BeldenHirschmann HiOS Switch Platform
SubsystemsGeneral OT
SectorsMultiple

What to Know

HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch. (NVD)

What to Do

Monitor Belden's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-15620
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-15620
Vendor advisoryhttps://assets.belden.com/m/702a656e81736b04/original/PSIRT-2_Web_Interface_HiOS.pdf