<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T17:18:38.439451+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-598</id>
    <title>certfr-2019-avi-598 — De multiples vulnérabilités ont été découvertes dans Moxa AWK-3121.
Certaines d'entre elles permettent à un attaquant d…</title>
    <updated>2026-10-08T17:18:38.443703+00:00</updated>
    <content>certfr-2019-avi-598</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-17003</id>
    <title>cnvd-2019-17003</title>
    <updated>2026-10-08T17:18:38.443740+00:00</updated>
    <content>cnvd-2019-17003</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-17003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-64758</id>
    <title>EUVD-2026-64758</title>
    <updated>2026-10-08T17:18:38.443755+00:00</updated>
    <content>EUVD-2026-64758</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-64758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10696</id>
    <title>fkie_cve-2018-10696</title>
    <updated>2026-10-08T17:18:38.443768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-10696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-353w-gjcf-9cx8</id>
    <title>GHSA-353w-gjcf-9cx8</title>
    <updated>2026-10-08T17:18:38.443795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-353w-gjcf-9cx8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-10696</id>
    <title>gsd-2018-10696</title>
    <updated>2026-10-08T17:18:38.443811+00:00</updated>
    <content>gsd-2018-10696</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-10696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-337-02</id>
    <title>ICSA-19-337-02 — Moxa AWK-3121</title>
    <updated>2026-10-08T17:18:38.443822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The device uses HTTP traffic by default allowing insecure communication to the web server, which could allow an attacker to compromise sensitive data such as credentials.CVE-2018-10690 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). An attacker can navigate to a URL and download the system log without authentication, which may allow access to sensitive information.CVE-2018-10691 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). A cross-site scripting attack allows access to session cookies, which may allow an attacker to login into the device.CVE-2018-10692 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An unauthorized user may execute network troubleshooting commands to cause a buffer overflow condition, which may allow the attacker to execute commands on the device.CVE-2018-10693 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The Wi-Fi connection used to set up the device is not encrypted by default, which may allow an attacker to capture sensitive data.CVE-2018-10694 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculat…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-337-02"/>
  </entry>
</feed>
