CVE-2024-14028: Multiple implicit reads in parallel can result in a crash or denial of service
Published Mar 27, 2026
·Updated
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02.
Affected Software
2 affected components
Softing Smartlink Hw-dp<=1.31
Softing smartLink HW-PN<1.02
Remediation
Information
Update firmware for
smartLink HW-DP: to 1.32
smartLink HW-PN: to 1.02.
Event History
Mar 27, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-14028?
CVE-2024-14028 has a high severity rating due to its potential to cause denial of service.
2
How can I mitigate CVE-2024-14028?
Mitigation of CVE-2024-14028 involves upgrading the affected Softing smartLink HW-DP to version 1.31 or higher and the smartLink HW-PN to version 1.02 or higher.
3
What are the potential impacts of CVE-2024-14028?
CVE-2024-14028 could lead to crashes or denial of service affecting the webserver functionality of the devices.
4
Which products are affected by CVE-2024-14028?
The affected products for CVE-2024-14028 are Softing smartLink HW-DP versions up to 1.31 and smartLink HW-PN versions before 1.02.
5
Can CVE-2024-14028 be exploited remotely?
Yes, CVE-2024-14028 can be exploited remotely through its HTTP interface.