CVE-2025-27450
EUVD-2025-1984903.07.2025, 12:15
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| endress | meac300-fnade4_firmware | 𝑥 ≤ 0.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References