CVE-2025-10685
High
|7.7Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to execute arbitrary code on affected Softing Industrial Automation web server modules, potentially taking control of the device. It can be exploited if the attacker has access to the network where the devices are located and is using specific versions of the software.
Technical Description
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:L/U:RedExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$2,474($1K-$5K)
Vendor Response
Grade APatched in 0 days
Quick Information
Published
Mar 16, 2026
22 days ago
Last Modified
Mar 16, 2026
22 days ago