PT-2025-27777 · Endress+Hauser+2 · Endress+Hauser Meac300-Fnade4+2

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-27448

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: The product name cannot be determined.
Description: The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-11703
CVE-2025-27448

Affected Products

Endress+Hauser Meac300-Fnade4
Meac300-Fnade4
Meac300-Fnade4 Firmware