CVE-2025-15620

HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:belden:hios_switch:*:*:*:*:*:*:*:*
cpe:2.3:a:belden:hios_switch:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-02 21:16

Updated : 2026-07-24 21:10


NVD link : CVE-2025-15620

Mitre link : CVE-2025-15620

CVE.ORG link : CVE-2025-15620


JSON object : View

Products Affected

belden

  • hios_switch
CWE
CWE-306

Missing Authentication for Critical Function