PT-2026-30262 · Undefined · Undefined
CVE-2018-25236
·
Published
2026-04-03
·
Updated
2026-07-21
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hirschmann HiOS and HiSecOS RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE (affected versions not specified)
Description
An authentication bypass exists in the HTTP(S) management module. This issue allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP requests. The flaw stems from improper authentication handling, enabling an attacker to assume the authentication status and privileges of a previously authenticated user without providing valid credentials.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined