Back to overview

Endress+Hauser: Multiple products affected by Qualcomm vulnerabilities

VDE-2025-107
Last update
12/05/2025 12:00
Published at
12/05/2025 12:00
Vendor(s)
Endress+Hauser AG
External ID
VDE-2025-107
CSAF Document

Summary

Multiple vulnerabilities in a Qualcomm component have been reported in a closed-source report. This component is an integral part of the radio chip found in several Endress+Hauser products.

Impact

Due to the closed-source nature of the report, the impact remains uncertain. In the worst-case scenario, this could lead to a loss of availability, integrity, and confidentiality.

In the case of the Liquiline Edge Module EMR, integrity and confidentiality are not affected due to the system architecture. The TLS connection to the Netilion cloud is fully managed by the integrated Linux system, which ensures end-to-end encryption. The Qualcomm radio chip is only used to transmit already encrypted data over the mobile network. Nevertheless, a complete loss of availability is still possible.

Affected Product(s)

Model no. Product name Affected versions
CYY7 Endress+Hauser Liquiline Edge Module EMR Firmware <01.02.00
5W8C Endress+Hauser Promag W 800 Firmware <01.00.08

Vulnerabilities

Expand / Collapse all

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Incorrect Calculation of Buffer Size (CWE-131)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Improper Validation of Array Index (CWE-129)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Improper Validation of Array Index (CWE-129)
References

Published
01/20/2026 08:54
Weakness
Incorrect Calculation of Buffer Size (CWE-131)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Integer Underflow (Wrap or Wraparound) (CWE-191)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Improper Access Control (CWE-284)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Improper Validation of Array Index (CWE-129)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Incorrect Type Conversion or Cast (CWE-704)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Improper Access Control (CWE-284)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Double Free (CWE-415)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Write (CWE-787)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Improper Validation of Array Index (CWE-129)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Improper Validation of Array Index (CWE-129)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Use of Uninitialized Resource (CWE-908)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Reachable Assertion (CWE-617)
References

Published
01/20/2026 08:54
Weakness
Reachable Assertion (CWE-617)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Divide By Zero (CWE-369)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
References

Published
01/20/2026 08:54
Weakness
Reachable Assertion (CWE-617)
References

Published
01/20/2026 08:54
Weakness
Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Published
01/20/2026 08:54
Weakness
Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
References

Published
01/20/2026 08:54
Weakness
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
References

Published
01/20/2026 08:54
Weakness
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
References

Published
01/20/2026 08:54
Weakness
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
References

Published
01/20/2026 08:54
Weakness
Improper Input Validation (CWE-20)
References

Published
01/20/2026 08:54
Weakness
Integer Overflow or Wraparound (CWE-190)
References

Published
01/20/2026 08:54
Weakness
Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
References

Published
01/20/2026 08:54
Weakness
Incomplete Cleanup (CWE-459)
References

Published
01/20/2026 08:54
Weakness
Observable Discrepancy (CWE-203)
References

Published
01/20/2026 08:54
Weakness
Observable Discrepancy (CWE-203)
References

Published
01/20/2026 08:54
Weakness
NULL Pointer Dereference (CWE-476)
References

Published
01/20/2026 08:54
Weakness
Out-of-bounds Read (CWE-125)
References

Mitigation

If a firmware update is no longer possible, it is recommended to replace the device.

Remediation

Endress+Hauser has released an updated firmware for the affected device that includes a security patch for the radio chip to address this vulnerability. Customers are encouraged to update their devices to the latest firmware version as soon as possible. For assistance, please contact your local Endress+Hauser service center.

Acknowledgments

Endress+Hauser AG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 12/05/2025 12:00 Initial version