Improper URL Checks in Softing Industrial Automation GmbH's SmartLink Products
CVE-2025-10461

5.3MEDIUM

Key Information:

Vendor

Softing

Vendor
CVE Published:
16 March 2026

What is CVE-2025-10461?

The vulnerability in Softing Industrial Automation GmbH's smartLinks products arises from improper validation of URLs within the webserver. This flaw allows unauthorized access to sensitive files due to global file reads, impacting both smartLink SW-HT and smartLink SW-PN versions. Proper remediation is crucial to secure these systems from potential exploitation.

Affected Version(s)

smartLink SW-HT 0 <= 1.42

smartLink SW-PN 0 <= 1.03

smartLink SW-HT 1.43

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OpenVAS
.