Hirschmann HiOS/HiSecOS Auth Bypass (CVE-2018-25236)
CVE-2018-25236
CVE-2018-25236: Remote unauthenticated attacker gains full admin control over Hirschmann HiOS/HiSecOS devices. Patch to fixed firmware immediately to prevent network takeover.
Patch now - CVE-2018-25236 is a critical authentication bypass in Hirschmann HiOS and HiSecOS that grants a remote, unauthenticated attacker full administrative control over affected industrial switches, firewalls, and routers. Update all devices to patched firmware releases immediately.
Overview
A critical vulnerability, CVE-2018-25236, exists in the HTTP(S) management interfaces of multiple Hirschmann operating systems, including HiOS and HiSecOS. The flaw is an authentication bypass that allows a remote attacker with no credentials to gain administrative control over affected network devices.
Vulnerability Details
The vulnerability resides in the web management module. It improperly handles authentication sessions, allowing an unauthenticated attacker to craft specific HTTP requests that trick the system into granting them the privileges of a previously logged-in administrator. No user interaction is required, and the attack can be performed over the network, making it highly exploitable.
Affected Products
This vulnerability impacts a wide range of Hirschmann industrial networking products running the affected operating systems. The list includes:
- RSP, RSPE, RSPS, and RSPL switches
- MSP switches
- EES and EESX switches
- GRS, OS, and RED devices
- EAGLE firewalls
Impact
The impact of successful exploitation is severe. An attacker could gain complete administrative access to the device. This would enable them to:
- Disrupt network operations by reconfiguring or disabling the device.
- Intercept, modify, or block network traffic.
- Use the compromised device as a foothold to launch further attacks deeper into the industrial or enterprise network.
- Permanently alter device configurations, leading to sustained operational issues.
Remediation and Mitigation
The primary and most critical action is to apply the vendor-provided patches. Hirschmann has released fixed versions of HiOS and HiSecOS to address this vulnerability. Administrators must identify all affected devices in their inventory and upgrade them to the patched firmware immediately.
If immediate patching is not possible, the following temporary mitigation strategies should be considered:
- Restrict Network Access: Use firewall rules and access control lists (ACLs) to restrict access to the HTTP(S) management interfaces (typically ports 80 and 443) of affected devices. Only allow connections from trusted, necessary administrative networks.
- Use Alternative Management: If available, disable the HTTP(S) management interface and use a more secure out-of-band management method, such as a dedicated console connection or a separate management network.
- Monitor for Anomalies: Implement network monitoring for unexpected configuration changes or unauthorized access attempts on these devices.
Security Insight
This vulnerability highlights the persistent risk of logic flaws in authentication mechanisms for embedded and industrial systems, where web interfaces are common. Similar to the widespread impact of authentication bypasses in consumer routers, flaws in critical infrastructure networking gear like Hirschmann’s can have cascading effects on physical operations, underscoring why these devices are increasingly targeted. For more on how complex software frameworks can introduce critical risks, see our coverage of LangChain and LangGraph vulnerabilities.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an ...
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vu...
openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-...
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. Th...