By Abinaya
Publication Date: 2026-02-23 12:38:00
The security bulletin published on February 19, 2026 addresses a remote flaw in HPE Telco Service Activator that could allow attackers to bypass access restrictions.
According to HPE, the problem arises from the Undertow HTTP server core used by the product.
The failure is a bad input validation condition where the server cannot correctly validate the Host header in incoming HTTP requests.
In real-world deployments, many applications and gateways rely on the Host header to enforce allow lists, route requests, or apply security rules.
| CVE ID | cvss | Product | Component | Vulnerability type | attack vector | Impact | Affected versions |
|---|---|---|---|---|---|---|---|
| CVE-2025-12543 | 9.6 (Critical) | HPE Telecom Services Enabler | Undertow HTTP Server (core) | Incorrect host header validation | Remote (HTTP request) | Access restriction bypass, possible unauthorized access | Versions prior to 10.5.0 |
When that header can be abused, an attacker can achieve the functionality…



