216.73.217.22

CVE-2018-25237

· Published 03/04/2026 22:16 · Modified 03/04/2026 22:16

Labels: CVE-2018-25237 2026-04-03CVE-2018-25237CWE-120[email protected]

Essential information

Published
03/04/2026 22:16
Modified
03/04/2026 22:16
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hirschmann / hisecos cpe:2.3:a:hirschmann:hisecos:<05.3.03:*:*:*:*:*:*:*

References