CVE-2024-14028 PUBLISHED

Multiple implicit reads in parallel can result in a crash or denial of service

Assigner: Softing
Reserved: 23.03.2026 Published: 27.03.2026 Updated: 27.03.2026

Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor Softing
Product smartLink HW-DP
Versions Default: unaffected
  • affected from 0 to 1.31 (incl.)
  • Version 1.32 is unaffected
Vendor Softing
Product smartLink HW-PN
Versions Default: unaffected
  • affected from 0 to 1.02 (excl.)
  • Version 1.02 is unaffected

Solutions

Update firmware for smartLink HW-DP: to 1.32 smartLink HW-PN: to 1.02.

References

Problem Types

  • CWE-416 Use after free CWE

Impacts

  • CAPEC-469 HTTP DoS