Improper Locking Vulnerability in Softing Industrial Automation Gateways
CVE-2025-10151

7.2HIGH

What is CVE-2025-10151?

An improper locking vulnerability has been identified in the gateways produced by Softing Industrial Automation GmbH. This issue can lead to the exposure of infected memory and resources, potentially compromising the integrity and performance of the affected systems. The vulnerability specifically impacts the smartLink HW-PN products from version 1.02 to 1.03 and the smartLink HW-DP in version 1.31. Organizations utilizing these products should review their configurations and apply recommended security updates to mitigate possible risks.

Affected Version(s)

smartLink HW-DP 0 <= 1.31

smartLink HW-PN 1.02 <= 1.03

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.