CVE-2026-89025: Belden Hirschmann Hios Switch Platform

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

Affected products

  • Belden Hirschmann Hios Switch Platform: from 07.0.0, up to and including 07.1.11; from 08.0.0, up to and including 08.7.09; from 09.0.00, up to and including 09.0.12; from 09.3.00, up to and including 09.3.02; from 10.0.0, up to and including 10.3.07; version 10.4.00 only; …

Published 2026-09-15. Last modified 2026-09-24.