Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2018-25237

A buffer overflow in the HTTPS login interface of Hirschmann HiSecOS devices allows attackers to crash the device or execute code when RADIUS authentication is enabled. The flaw is triggered by passwords longer than 128 characters.

publishedApr 3, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
54th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Hirschmann HiSecOS devices running firmware versions earlier than 05.3.03 with RADIUS authentication enabled.

02

Real-world impact

An attacker could cause the device to stop working or run malicious code, potentially taking control of the network device.

03

Why this severity

The CVSS score of 9.3 reflects the high impact of remote code execution and denial of service, with no authentication or user interaction required.

04

What to do about it

official fix available
recommended steps
  1. 01Verify the current firmware version of the HiSecOS device.
  2. 02Download the latest firmware (05.3.03 or later) from the Hirschmann website.
  3. 03Apply the firmware update following the vendor’s update procedure.
  4. 04Reboot the device to complete the upgrade.
  5. 05Verify that the HTTPS login interface works and that RADIUS authentication is functional.

NVD description indicates that versions prior to 05.3.03 are vulnerable; upgrade to 05.3.03 or later.

05

Timeline

  1. Apr 3, 2026 · Apr 3, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 15d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 21, 2026 · 15d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →