Status: UPDATED | Advisory ID: CVE-2025-15620
| CVE | CVE-2025-15620 |
| CVSS Score / Version | 8.6 (High) / CVSS v3.1 |
| Updated | 2026-07-24 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Belden hios_switch and Belden Hirschmann HiOS Switch Platform |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Belden | hios_switch | ||
| Belden | Hirschmann HiOS Switch Platform |
| Subsystems | General OT |
| Sectors | Multiple |
HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch. (NVD)
Monitor Belden's web page for any future patch releases. See vendor advisory link below.