📦 Meac300 Fnade4 Firmware

by Endress

🔍 What is Meac300 Fnade4 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27460

HIGH CVSS 7.6 Jul 3, 2025

This vulnerability allows attackers with physical access to bypass Windows login security by booting from an alternative operating system, enabling full read/write access to unencrypted hard drives. I...

CVE-2025-27461

HIGH CVSS 7.6 Jul 3, 2025

This vulnerability allows automatic login to the EPC2 Windows user account without password authentication during device startup. It affects industrial control systems and devices from SICK AG that us...

CVE-2025-27456

HIGH CVSS 7.5 Jul 3, 2025

This vulnerability allows attackers to perform brute-force attacks against SMB server login mechanisms due to insufficient rate limiting. It affects systems running vulnerable SMB server implementatio...

CVE-2025-1710

HIGH CVSS 7.5 Jul 3, 2025

CVE-2025-1710 is an authentication brute-force vulnerability in maxView Storage Manager that allows attackers to guess credentials through repeated login attempts. This affects organizations using vul...

CVE-2025-27447

HIGH CVSS 7.4 Jul 3, 2025

This cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript into the web application via specially crafted URLs. When an authenticated administrator clicks such a lin...

CVE-2025-27449

HIGH CVSS 7.5 Jul 3, 2025

The MEAC300-FNADE4 device lacks rate limiting for authentication attempts, allowing attackers to systematically guess passwords via brute-force attacks. This affects all users of this specific industr...

CVE-2025-1708

HIGH CVSS 8.6 Jul 3, 2025

This SQL injection vulnerability in PostgreSQL allows attackers to execute arbitrary SQL commands and dump database contents. It affects applications using vulnerable PostgreSQL configurations. Organi...

CVE-2025-27452

MEDIUM CVSS 5.3 Jul 3, 2025

This vulnerability affects Apache httpd webservers running the MEAC300-FNADE4 web application with unnecessary modules enabled. It allows directory listing, potentially exposing sensitive files and di...

CVE-2025-27454

MEDIUM CVSS 4.3 Jul 3, 2025

This CSRF vulnerability allows attackers to trick authenticated users into performing unintended actions on their behalf. Attackers can craft malicious requests that execute with the victim's session ...

CVE-2025-27455

MEDIUM CVSS 4.3 Jul 3, 2025

This clickjacking vulnerability allows attackers to embed the web application in malicious frames, tricking users into clicking hidden elements. This could lead to unauthorized actions or data exposur...

CVE-2025-27457

MEDIUM CVSS 6.5 Jul 3, 2025

CVE-2025-27457 is a cleartext transmission vulnerability in VNC communications that allows attackers to intercept unencrypted traffic between VNC servers and clients. This exposes sensitive data like ...

CVE-2025-27453

MEDIUM CVSS 5.3 Jul 3, 2025

This vulnerability allows client-side scripts (like JavaScript) to access the PHPSESSION cookie because the HttpOnly flag is disabled. This affects web applications that use PHP sessions without prope...

CVE-2025-27458

MEDIUM CVSS 6.5 Jul 3, 2025

This vulnerability in VNC authentication allows attackers to capture challenge-response pairs from unencrypted network traffic and attempt to derive the password through offline brute-force attacks. I...

CVE-2025-27448

MEDIUM CVSS 6.8 Jul 3, 2025

This cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript into dashboard names in a web application. When users view these dashboards, the injected code executes in...

CVE-2025-27450

MEDIUM CVSS 6.5 Jul 3, 2025

This vulnerability in the MEAC300-FNADE4 device allows session hijacking because cookies lack the Secure attribute. Attackers can intercept PHPSESSID cookies via unencrypted HTTP connections, potentia...

CVE-2025-27451

MEDIUM CVSS 5.3 Jul 3, 2025

This vulnerability allows attackers to enumerate valid usernames by observing different error messages for incorrect passwords versus non-existent usernames during failed login attempts. This affects ...

CVE-2025-1709

MEDIUM CVSS 6.5 Jul 3, 2025

This vulnerability exposes PostgreSQL database credentials stored in plain text (partially base64 encoded) in SICK industrial control systems. Attackers who gain access to affected systems can extract...