CVE-2018-25237 is a critical buffer overflow vulnerability impacting Hirschmann HiSecOS devices prior to version 05.3.03, specifically within the HTTPS login interface when RADIUS authentication is enabled. This flaw allows a remote, unauthenticated attacker to submit an excessively long password, leading to a denial of service or arbitrary code execution. Rated 9.8 CRITICAL (CVSSv3.1), it carries a high impact on confidentiality, integrity, and availability with low attack complexity. Although not listed in CISA's KEV catalog and lacking public exploit code, its inclusion on a "Hot List" suggests ongoing concern, despite minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Belden | Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One) | >= 0, <= 05.3.02CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.