CVE-2025-27461: High severity Endress Meac300-fnade4 Firmware vulnerability
Published Jul 3, 2025
·Updated
During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
Affected Software
2 affected components
All of the following
Endress Meac300-fnade4 Firmware
Endress Meac300-fnade4
Event History
Jul 3, 2025
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27461?
CVE-2025-27461 is considered a high severity vulnerability due to the automatic login without password protection.
2
What systems are affected by CVE-2025-27461?
CVE-2025-27461 affects the Endress Meac300-fnade4 Firmware.
3
How do I fix CVE-2025-27461?
To mitigate CVE-2025-27461, configure the device settings to require a password during startup.
4
What are the risks associated with CVE-2025-27461?
The risks include unauthorized access to the device, leading to potential data manipulation or breaches.
5
Is there a patch available for CVE-2025-27461?
Currently, there is no publicly available patch for CVE-2025-27461; users should implement manual security measures.