CVE-2018-25237 PUBLISHED

Hirschmann HiSecOS Buffer Overflow via HTTPS Login

Assigner: VulnCheck
Reserved: 03.04.2026 Published: 03.04.2026 Updated: 03.04.2026

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Belden
Product Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One)
Versions Default: affected
  • Version 05.3.03 is unaffected
  • affected from 0 to 05.3.02 (incl.)

References

Problem Types

  • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE