CVE-2025-10461 PUBLISHED

Global file reads caused by improper URL checks in webserver

Assigner: Softing
Reserved: 15.09.2025 Published: 16.03.2026 Updated: 16.03.2026

Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access.

This issue affects

smartLink SW-HT: through 1.42

smartLink SW-PN: through 1.03.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/AU:Y/R:A/RE:L/U:Green
CVSS Score: 5.3

Product Status

Vendor Softing
Product smartLink SW-HT
Versions Default: unaffected
  • affected from 0 to 1.42 (incl.)
  • Version 1.43 is unaffected
Vendor Softing
Product smartLink SW-PN
Versions Default: unaffected
  • affected from 0 to 1.03 (incl.)
  • Version 1.04 is unaffected

Solutions

This issue is fixed in

smartLink SW-HT: 1.43

smartLink SW-PN: 1.04

Credits

  • OpenVAS tool

References

Problem Types

  • CWE-20 Improper Input Validation CWE

Impacts

  • CAPEC-497 File Discovery