---
id: CVE-2026-13148
title: >-
  Missing release of memory after effective lifetime vulnerability in Softing
  smartLink allows resource leak exposure.


  This issue affects smartLink HW-PN: from 1.04 before 1.10.
summary: >-
  Missing release of memory after effective lifetime vulnerability in Softing
  smartLink allows resource leak exposure.


  This issue affects smartLink HW-PN: from 1.04 before 1.10.
severity: medium
cvss: 6.3
cvssVector: >-
  CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:L/AU:Y/R:A/RE:L/U:Red
cwe:
  - CWE-401
vendor: Softing
product: smartLink HW-PN
affected:
  - smartlink_hw-pn >= 1.04 < 1.10
published: '2026-09-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13148'
references:
  - url: >-
      https://industrial.softing.com/fileadmin/psirt/downloads/2026/CVE-2026-13148.html
    label: 10de8ef9-5c89-4b17-8228-e97b74acf4bd
  - url: >-
      https://industrial.softing.com/fileadmin/psirt/downloads/2026/CVE-2026-13148.json
    label: 10de8ef9-5c89-4b17-8228-e97b74acf4bd
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-04T12:58:42.337429Z'
cvssSource: cna
ingestedAt: '2026-09-13T14:42:51.112Z'
epss: 0.00235
epssPercentile: 0.1278
---

## Overview

Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure.

This issue affects smartLink HW-PN: from 1.04 before 1.10.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
