Hirschmann HiOS and HiSecOS Authentication Bypass Vulnerability in HTTP Management Module

Vulnerability

An authentication bypass vulnerability has been identified in the HTTP(S) management module of Hirschmann HiOS and HiSecOS products, including RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, and EAGLE. This vulnerability allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP requests. Exploitation of this vulnerability takes advantage of improper authentication handling, enabling attackers to access the authentication status and privileges of previously authenticated users without valid credentials.

Impact

Exploitation of this vulnerability could allow attackers to bypass authentication and gain administrative access to the device, enabling them to perform actions such as downloading or uploading configurations, changing firmware, or executing other administrative functions.

Remediation

Users are advised to update to Hirschmann HiOS versions 06.1.05 or 07.0.00, or to HiSecOS EAGLE versions 03.0.03 or 03.1.00.

Added: Apr 3, 2026, 11:28 PM
Updated: Apr 3, 2026, 11:28 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
7.3
remediation
7.7
relevance
4.9
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.