By Nicole Willing
Publication Date: 2026-02-23 15:30:00
Hewlett Packard Enterprise (HPE) has issued a safety bulletin warning customers about a serious vulnerability in HPE Telco Service Activator, a platform widely used by telecommunications operators to automate service delivery.
The issue is tracked as CVE-2025-12543, HPE stated.
“This vulnerability is caused by a flaw in the Undertow HTTP Server core that does not properly validate the Host header in incoming HTTP requests.”
In plain language, the software does not properly validate the Host header in incoming HTTP requests. HPE described the vulnerability as a remote access restriction bypass vulnerability, meaning that an unauthenticated attacker could create malicious HTTP requests to bypass access controls implemented on the server. That gives the defect a CVSS rating of 9.6, which is firmly in “critical” territory.
Because the attack does not require prior authorization or deep technical privileges, it is especially dangerous in exposed locations…



