PT-2025-33296 · Espec North America · Espec North America Web Controller

CVE-2025-27847

·

Published

2025-08-14

·

Updated

2025-08-16

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: ESPEC North America Web Controller versions prior to 3.3.8
Description: The web controller does not revoke user session privileges upon logout via the /api/v4/auth/ endpoint, potentially allowing continued access.
Recommendations: Update to version 3.3.8 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27847

Affected Products

Espec North America Web Controller