Heap-based Buffer Overflow Vulnerability in Softing Industrial Automation SmartLink Products
CVE-2025-10685

7.7HIGH

Key Information:

Vendor

Softing

Vendor
CVE Published:
16 March 2026

What is CVE-2025-10685?

A heap-based buffer overflow vulnerability exists in the webserver modules of Softing Industrial Automation GmbH's SmartLink products, specifically affecting versions of smartLink SW-PN up to 1.03 and smartLink SW-HT up to 1.42. This flaw allows attackers to exploit the overflow conditions, potentially leading to arbitrary code execution or service disruptions.

Affected Version(s)

smartLink SW-HT 0 <= 1.42

smartLink SW-PN 0 <= 1.03

smartLink SW-HT 1.43

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Frank Renner
.