HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.
References
Configurations
No configuration.
History
03 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Apr 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch. |
02 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 21:16
Updated : 2026-04-03 23:17
NVD link : CVE-2025-15620
Mitre link : CVE-2025-15620
CVE.ORG link : CVE-2025-15620
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
