CVE-2025-27450: Medium severity MEAC MEAC300-FNADE4 vulnerability
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27450?
CVE-2025-27450 is considered a high-severity vulnerability due to the potential for cookie interception and unauthorized access.
How do I fix CVE-2025-27450?
To mitigate CVE-2025-27450, ensure that the Secure attribute is set on all cookies, particularly the PHPSESSID cookie.
What systems are affected by CVE-2025-27450?
CVE-2025-27450 specifically affects the MEAC300-FNADE4 device.
What types of attacks can be executed due to CVE-2025-27450?
An attacker can exploit CVE-2025-27450 to perform cookie interception attacks by tricking users into an unencrypted HTTP connection.
Is there a workaround for CVE-2025-27450?
The primary workaround for CVE-2025-27450 is to review and update cookie settings to include the Secure attribute.