Softing
First CVE: Aug 21, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Softing as a CNA, 0.0% affect products that Softing develops as a vendor.
100.0%
Self-reported: 0Third-party: 8
Of all the CVEs published that affect products developed by Softing, 0.0% are self-published by Softing as a CNA.
100.0%
Self-published: 0Published by other CNAs: 44
Trends Over Time
The number and severity of CVEs published by Softing over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2025
11 months ago
Most Recent CVE
Mar 27, 2026
119 days ago
Top CVEs
All CVEs published by Softing as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7390CRITICAL A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication. | Aug 21, 2025 | 9.1 | 34 | NO | NO |
CVE-2025-10150HIGH Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects
smartLink HW-PN: from 1.02 through 1.03
smartLink H | Oct 28, 2025 | 8.7 | 27 | NO | NO |
CVE-2025-10685HIGH Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects:
| Mar 16, 2026 | 7.7 | 25 | NO | NO |
CVE-2023-7339MEDIUM Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers.
This issue affects
pnGate: through 1.30
epGate: through 1.30
mbGat | Mar 27, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-10151HIGH Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects
smartLink HW-PN: from 1.02 th | Oct 28, 2025 | 7.2 | 24 | NO | NO |
CVE-2024-14028MEDIUM Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS.
This issue affects:
smartLink HW-DP: through 1.31
smartLink HW-PN: before 1.02 | Mar 27, 2026 | 6.5 | 23 | NO | NO |
CVE-2025-13406MEDIUM NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43. | Mar 17, 2026 | 6.8 | 22 | NO | NO |
CVE-2025-10461MEDIUM Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access.
This issue affec | Mar 16, 2026 | 5.3 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
50%
38%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None4 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Softing as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Softing as a CNA — matched by CVE ID, not by organization name.