<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T19:31:45.647244+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-179534</id>
    <title>EUVD-2026-179534</title>
    <updated>2026-10-04T19:31:45.650872+00:00</updated>
    <content>EUVD-2026-179534</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-179534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12511</id>
    <title>fkie_cve-2020-12511</title>
    <updated>2026-10-04T19:31:45.650905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-12511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whqx-xf73-2457</id>
    <title>GHSA-whqx-xf73-2457</title>
    <updated>2026-10-04T19:31:45.650936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whqx-xf73-2457"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-12511</id>
    <title>gsd-2020-12511</title>
    <updated>2026-10-04T19:31:45.650953+00:00</updated>
    <content>gsd-2020-12511</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-12511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-038</id>
    <title>VDE-2020-038 — Pepperl+Fuchs: Multiple vulnerabilites in Comtrol IO-Link Master</title>
    <updated>2026-10-04T19:31:45.650964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. 
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes. During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o). Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-038"/>
  </entry>
</feed>
