CVE Feed

    Dashboard / CVE / CVE-2018-25237

    CVE-2018-25237

    Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

    Published:Apr 3, 2026
    Last Modified:Apr 7, 2026
    EPS:Apr 3, 2026
    EPSS Score:0.0008
    CVSS Score:9.8

    Affected Products

    Vendor
    Belden
    Product
    Hirschmann Eagle One
    Vendor
    Belden
    Product
    Hirschmann Hisecos

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High