# CVE-2026-89025

## Summary

- **CVE ID:** CVE-2026-89025
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-755
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. This vulnerability has been addressed in versions 07.1.12, 08.7.10, 09.0.13, 09.3.03, 10.3.08, and 10.5.00.

## Affected Products

- Belden — Hirschmann HiOS Switch Platform (07.0.0)
- Belden — Hirschmann HiOS Switch Platform (07.1.12)
- Belden — Hirschmann HiOS Switch Platform (08.0.0)
- Belden — Hirschmann HiOS Switch Platform (08.7.10)
- Belden — Hirschmann HiOS Switch Platform (09.0.00)
- Belden — Hirschmann HiOS Switch Platform (09.0.13)
- Belden — Hirschmann HiOS Switch Platform (09.3.00)
- Belden — Hirschmann HiOS Switch Platform (09.3.03)
- Belden — Hirschmann HiOS Switch Platform (10.0.0)
- Belden — Hirschmann HiOS Switch Platform (10.3.08)
- Belden — Hirschmann HiOS Switch Platform (10.4.00)
- Belden — Hirschmann HiOS Switch Platform (10.5.00)

## References

- [CNA](https://assets.belden.com/asset/2ba884e3-c0c9-40f6-aa22-a9e852b20af4/PSIRT-6_HTTPS_Vulnerability_HiOS.pdf)
- [CNA](https://www.vulncheck.com/advisories/hirschmann-hios-switch-platform-dos-via-malformed-http-request)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 36.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._