CVE-2025-27454: Endress MEAC300-FNADE4 Firmware
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's browser's saved authorization to execute the request.
Affected products
- Endress MEAC300-FNADE4 Firmware: up to and including 0.16.0
Published 2025-07-03. Last modified 2026-06-17.