<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:14:56.934045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-08520</id>
    <title>bdu:2023-08520</title>
    <updated>2026-10-04T03:14:57.016728+00:00</updated>
    <content>bdu:2023-08520</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-08520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210920</id>
    <title>EUVD-2026-210920</title>
    <updated>2026-10-04T03:14:57.016763+00:00</updated>
    <content>EUVD-2026-210920</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28395</id>
    <title>fkie_cve-2023-28395</title>
    <updated>2026-10-04T03:14:57.016778+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-28395"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-94w5-83fg-vhgc</id>
    <title>GHSA-94w5-83fg-vhgc</title>
    <updated>2026-10-04T03:14:57.016807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-94w5-83fg-vhgc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-28395</id>
    <title>gsd-2023-28395</title>
    <updated>2026-10-04T03:14:57.016823+00:00</updated>
    <content>gsd-2023-28395</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-28395"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-082-06</id>
    <title>ICSA-23-082-06 — ProPump and Controls Osprey Pump Controller (Update A)</title>
    <updated>2026-10-04T03:14:57.016834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Osprey Pump Controller versions prior to release 20230518 are vulnerable to a predictable weak session token generation algorithm and could aid in authentication and authorization bypass. This could allow a cyber threat actor to hijack a session by predicting the session ID and gain unauthorized access to the product. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated file disclosure. Cyber threat actors could use a GET parameter to force the affected device to disclose arbitrary files and sensitive system information. Osprey Pump Controller versions prior to release 20230518 have a hidden administrative account with a hardcoded password that allows full access to the web management interface configuration. The account is not visible in the Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation of the device. Osprey Pump Controller versions prior to release 20230518 are vulnerable to an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script. Osprey Pump Controller versions prior to release 20230518 are vulnerable an unauthenticated OS command injection vulnerability. Threat actors could exploit this vulnerability to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-082-06"/>
  </entry>
</feed>
