<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:28:20.609856+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-123</id>
    <title>certfr-2022-avi-123 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T23:28:20.726320+00:00</updated>
    <content>certfr-2022-avi-123</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-123"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-13559</id>
    <title>EUVD-2026-13559</title>
    <updated>2026-10-02T23:28:20.726374+00:00</updated>
    <content>EUVD-2026-13559</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-13559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22808</id>
    <title>fkie_cve-2022-22808</title>
    <updated>2026-10-02T23:28:20.726396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-22808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p6hc-w7h4-q55x</id>
    <title>GHSA-p6hc-w7h4-q55x</title>
    <updated>2026-10-02T23:28:20.726440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-942: Permissive Cross-domain Policy with Untrusted Domains vulnerability exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p6hc-w7h4-q55x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-22808</id>
    <title>gsd-2022-22808</title>
    <updated>2026-10-02T23:28:20.726469+00:00</updated>
    <content>gsd-2022-22808</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-22808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2022-039-02</id>
    <title>SEVD-2022-039-02 — EcoStruxure EV Charging Expert</title>
    <updated>2026-10-02T23:28:20.726486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure EV Charging Expert
(formerly known as EVlink Load Management System) products.
The EcoStruxure EV Charging Expert products are load management, access management and
supervision solutions for EV charging infrastructure.
Failure to apply the available remediations may risk potential unauthorized access to the
product’s web server, which could lead to tampering and compromise of the product’s settings
and accounts. Such tampering could lead to things like denial of service attacks, which could
result in unauthorized use of the managed EV charging stations, service interruptions, failure to
communicate with the supervision system and the modification and disclosure of the product’s
configuration.
In addition to applying the available remediations, to limit the risk of a product being
compromised, Schneider Electric recommends that customers follow and apply network security
best practices and ensure that the products are not accessible from the internet, as outlined in
the General Security Recommendations section</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2022-039-02"/>
  </entry>
</feed>
