CVE-2018-25237
A buffer overflow in the HTTPS login interface of Hirschmann HiSecOS devices allows attackers to crash the device or execute code when RADIUS authentication is enabled. The flaw is triggered by passwords longer than 128 characters.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Hirschmann HiSecOS devices running firmware versions earlier than 05.3.03 with RADIUS authentication enabled.
Real-world impact
An attacker could cause the device to stop working or run malicious code, potentially taking control of the network device.
Why this severity
The CVSS score of 9.3 reflects the high impact of remote code execution and denial of service, with no authentication or user interaction required.
What to do about it
- 01Verify the current firmware version of the HiSecOS device.
- 02Download the latest firmware (05.3.03 or later) from the Hirschmann website.
- 03Apply the firmware update following the vendor’s update procedure.
- 04Reboot the device to complete the upgrade.
- 05Verify that the HTTPS login interface works and that RADIUS authentication is functional.
NVD description indicates that versions prior to 05.3.03 are vulnerable; upgrade to 05.3.03 or later.
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.