PT-2026-30262 · Undefined · Undefined

CVE-2018-25236

·

Published

2026-04-03

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hirschmann HiOS and HiSecOS RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE (affected versions not specified)
Description An authentication bypass exists in the HTTP(S) management module. This issue allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP requests. The flaw stems from improper authentication handling, enabling an attacker to assume the authentication status and privileges of a previously authenticated user without providing valid credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25236

Affected Products

Undefined