<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:16:29.943007+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108471a7121</id>
    <title>9AKK108471A7121 — FLXeon Controllers Multiple vulnerabilities</title>
    <updated>2026-10-03T13:16:29.998914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.
 
FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed 
customers of this parameter.</p>
<p>An attacker can successfully exploit these vulnerabilities and could take remote control of the product 
and potentially insert and run arbitrary code.
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.</p>
<p>Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.</p>
<p>ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, 
CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108471a7121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252891</id>
    <title>EUVD-2026-252891</title>
    <updated>2026-10-03T13:16:29.998975+00:00</updated>
    <content>EUVD-2026-252891</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252891"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-48842</id>
    <title>fkie_cve-2024-48842</title>
    <updated>2026-10-03T13:16:29.998992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-48842"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2r6p-73q6-355q</id>
    <title>GHSA-2r6p-73q6-355q</title>
    <updated>2026-10-03T13:16:29.999015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2r6p-73q6-355q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-310-03</id>
    <title>ICSA-25-310-03 — ABB FLXeon Controllers</title>
    <updated>2026-10-03T13:16:29.999029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Credentials that are required for the functioning of the product cannot be stored in a HW supported secure storage as the product does not implement such a component.  A remote code execution is possible due to an improper input validation. Password hashes are stored using a vulnerable MD5 algorithm with low entropy on salt, stored in plain text on unencrypted partitions. Users can push files with full pathnames allowing file operations in off limits directories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-310-03"/>
  </entry>
</feed>
