Back

CRITICAL

Hirschmann HiSecOS Buffer Overflow via HTTPS Login

Published Apr 3, 2026

Description

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 3, 2026
Updated Oct 1, 2026
Reserved Apr 3, 2026
CISA Vulnrichment
Updated Apr 6, 2026
NVD
Status Awaiting Analysis
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a