216.73.216.6

CVE-2025-15620

· Published 02/04/2026 21:16 · Modified 03/04/2026 23:17

Labels: CVE-2025-15620 2026-04-02CVE-2025-15620CWE-306[email protected]

Essential information

Published
02/04/2026 21:16
Modified
03/04/2026 23:17
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hios / hios switch platform cpe:2.3:a:hios:hios_switch_platform:*:*:*:*:*:*:*:*

References