CVE-2018-25236 PUBLISHED

Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management

Assigner: VulnCheck
Reserved: 03.04.2026 Published: 03.04.2026 Updated: 03.04.2026

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Belden
Product Hirschmann HiOS
Versions Default: unaffected
  • affected from 0 to 05.07 (incl.)
  • affected from 0 to 06.1.04 (incl.)
  • affected from 0 to 06.2.00 (incl.)
  • Version 06.1.05 is unaffected
  • Version 07.0.00 is unaffected
  • Version 03.1.00 is unaffected
Vendor Belden
Product Hirschmann HiSecOS EAGLE
Versions Default: unaffected
  • affected from 0 to 03.00.02 (incl.)
  • Version 03.0.03 is unaffected

References

Problem Types

  • Improper Authentication (CWE-287) CWE