CVE-2018-25237

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.
Configurations

No configuration.

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Dispositivos Hirschmann HiSecOS versiones anteriores a la 05.3.03 contienen una vulnerabilidad de desbordamiento de búfer en la interfaz de inicio de sesión HTTPS cuando la autenticación RADIUS está habilitada que permite a atacantes remotos bloquear el dispositivo o ejecutar código arbitrario al enviar una contraseña de más de 128 caracteres. Los atacantes pueden explotar la comprobación de límites inadecuada en el manejo de contraseñas para desbordar un búfer de tamaño fijo y lograr la denegación de servicio o la ejecución remota de código.

03 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 22:16

Updated : 2026-07-21 07:10


NVD link : CVE-2018-25237

Mitre link : CVE-2018-25237

CVE.ORG link : CVE-2018-25237


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')