CVE-2025-10685 PUBLISHED

HTTP POST with specific higher content length leads into heap corruption

Assigner: Softing
Reserved: 18.09.2025 Published: 16.03.2026 Updated: 16.03.2026

Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects:

smartLink SW-PN: through 1.03

smartLink SW-HT: through 1.42

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/AU:Y/R:A/RE:L/U:Red
CVSS Score: 7.7

Product Status

Vendor Softing
Product smartLink SW-PN
Versions Default: unaffected
  • affected from 0 to 1.03 (incl.)
  • Version 1.04 is unaffected
Vendor Softing
Product smartLink SW-HT
Versions Default: unaffected
  • affected from 0 to 1.42 (incl.)
  • Version 1.43 is unaffected

Solutions

Update firmware for

smartLink SW-PN: to 1.04

smartLink SW-HT: to 1.43

Credits

  • Frank Renner finder

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers