CVE Vulnerabilities

CVE-2025-27452

Exposure of Information Through Directory Listing

Published: Jul 03, 2025 | Modified: Feb 06, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules

pose a risk to the webserver which enable dircetory listing.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Meac300-fnade4_firmwareEndress*0.16.0 (including)

Potential Mitigations

References