CVE-2025-10461: Global file reads caused by improper URL checks in webserver
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access.
This issue affects
smartLink SW-HT: through 1.42
smartLink SW-PN: through 1.03.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10461?
CVE-2025-10461 is considered a critical vulnerability due to potential unauthorized file access.
How do I fix CVE-2025-10461?
To mitigate CVE-2025-10461, upgrade your Softing smartLink SW-HT to version 1.43 or later and smartLink SW-PN to version 1.04 or later.
What products are affected by CVE-2025-10461?
CVE-2025-10461 affects Softing smartLink SW-HT versions up to 1.42 and smartLink SW-PN versions up to 1.03.
What type of vulnerability is CVE-2025-10461?
CVE-2025-10461 is categorized as a global file read vulnerability due to improper URL checks in the web server.
Can exploiting CVE-2025-10461 lead to data breaches?
Yes, exploiting CVE-2025-10461 can allow attackers to access sensitive files, potentially leading to data breaches.