PT-2025-27783 · Endress+Hauser+2 · Endress+Hauser Meac300-Fnade4+2

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-27454

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: The product name cannot be determined.
Description: The issue allows an attacker to trick a valid, logged-in user into submitting a web request that they did not intend, utilizing the victim's browser's saved authorization to execute the request. This is a case of cross-site request forgery.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-11705
CVE-2025-27454

Affected Products

Endress+Hauser Meac300-Fnade4
Meac300-Fnade4
Meac300-Fnade4 Firmware