Junglewise Threat Intelligence

CVE-2026-13148: Softing smartLink HW-PN memory leak in scan method

CVE-2026-13148 · Severity: info · CVSS 6.3 · Published 2026-09-04

Executive brief

Softing smartLink HW-PN is an industrial networking device used to link control systems and devices on a network. A memory leak in its scan method can cause resource exhaustion and performance degradation over time, potentially leading to system instability or denial of service if the device runs out of available memory.

Technical details

This vulnerability is a CWE-401 missing release of memory after effective lifetime issue in the scan method of smartLink HW-PN. The flaw allows accumulated memory allocation without proper deallocation, leading to resource leak exposure. The vulnerability is exploitable via the network with LOW attack complexity and requires LOW privileges; no user interaction is needed. An authenticated attacker can trigger memory exhaustion, causing secondary integrity and availability impacts (system instability, service degradation). Patch is available in version 1.10 and later.

Affected products

  • Softing smartLink HW-PN 1.04 before 1.10

Timeline

  • 2026-09-04: disclosed

References