<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:14:34.526689+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-183886</id>
    <title>EUVD-2026-183886</title>
    <updated>2026-10-03T16:14:34.603330+00:00</updated>
    <content>EUVD-2026-183886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-183886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31806</id>
    <title>fkie_cve-2022-31806</title>
    <updated>2026-10-03T16:14:34.603378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202208</id>
    <title>FSA-202208 — Festo: Multiple Festo products contain an unsafe default Codesys configuration</title>
    <updated>2026-10-03T16:14:34.603409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.</p>
<p>With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202208"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-796c-7jw3-fwpp</id>
    <title>GHSA-796c-7jw3-fwpp</title>
    <updated>2026-10-03T16:14:34.603433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-796c-7jw3-fwpp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31806</id>
    <title>gsd-2022-31806</title>
    <updated>2026-10-03T16:14:34.603448+00:00</updated>
    <content>gsd-2022-31806</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-329-05</id>
    <title>ICSA-25-329-05 — Festo Compact Vision System, Control Block, Controller, and Operator Unit products</title>
    <updated>2026-10-03T16:14:34.603459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-329-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-040</id>
    <title>VDE-2022-040 — WAGO: Multiple Vulnerabilities in Controller with WAGO I/O-Pro / CODESYS 2.3 Runtime</title>
    <updated>2026-10-03T16:14:34.603477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>UPDATE A: Solution has updated release datesUPDATE B: Solution has updated release datesThis Advisory is published with reference to:</p>
<p>CODESYS Advisory 2022-11 (Security update for CODESYS Control V2)
CODESYS Advisory 2022-12 (Security update for CODESYS V2 password transport)
CODESYS Advisory 2022-13 (Security update for CODESYS Gateway V2)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-040"/>
  </entry>
</feed>
