9.3
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Description
HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.
Basic Information
ID
CVE-2025-15620
Source
VulnCheck
Published
Apr 2, 2026 at 20:28
Modified
Apr 3, 2026 at 22:24
Affected Product
Vendor
Belden
Product
Hirschmann HiOS Switch Platform
Version
09.1.00
Affected Versions
Belden Hirschmann HiOS Switch Platform 09.1.00
Belden Hirschmann HiOS Switch Platform 10.0.00
Belden Hirschmann HiOS Switch Platform 10.0.00