Back

CRITICAL

Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management

Published Apr 3, 2026

Description

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 3, 2026
Updated Jul 15, 2026
Reserved Apr 3, 2026
CISA Vulnrichment
Updated Apr 6, 2026
NVD
Status Awaiting Analysis
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a