CVE-2025-10461

MEDIUM

Global file reads caused by improper URL checks in webserver

Title source: cna
STIX 2.1

Description

Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.

Scores

CVSS v4 5.3
EPSS 0.0037
EPSS Percentile 28.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:L/U:Green

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (4)
Softing/smartLink SW-HT < 1.42
Softing/smartLink SW-HT 1.43
Softing/smartLink SW-PN < 1.03
Softing/smartLink SW-PN 1.04
Published Mar 16, 2026
Tracked Since Mar 16, 2026