← All Advisories

CVE-2026-89025

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-89025

Key Details

CVECVE-2026-89025
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsBelden Hirschmann HiOS Switch Platform
Classified asCWE-755 (Improper Handling of Exceptional Conditions)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeldenHirschmann HiOS Switch Platform
SubsystemsGeneral OT
SectorsMultiple

What to Know

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00. (NVD)

What to Do

Monitor Belden's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89025
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89025