<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:44:29.161530+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04706</id>
    <title>bdu:2025-04706</title>
    <updated>2026-10-02T18:44:29.327504+00:00</updated>
    <content>bdu:2025-04706</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04706"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0360</id>
    <title>certfr-2025-avi-0360 — De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T18:44:29.327546+00:00</updated>
    <content>certfr-2025-avi-0360</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-erlang-otp-ssh-xyzzy</id>
    <title>cisco-sa-erlang-otp-ssh-xyZZy — Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025</title>
    <updated>2026-10-02T18:44:29.327565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On April 16, 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device.

The vulnerability is due to a flaw in the handling of SSH messages during the authentication phase.

For a description of this vulnerability, see the Erlang announcement ["https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-erlang-otp-ssh-xyzzy"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hg35040</id>
    <title>Withdrawn: CLEANSTART-2026-HG35040 — Erlang/OTP is a set of libraries for the Erlang programming language</title>
    <updated>2026-10-02T18:44:29.327596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: erlang</p>
<p>Multiple security vulnerabilities affect the erlang package. Erlang/OTP is a set of libraries for the Erlang programming language. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hg35040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272987</id>
    <title>EUVD-2026-272987</title>
    <updated>2026-10-02T18:44:29.327619+00:00</updated>
    <content>EUVD-2026-272987</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32433</id>
    <title>fkie_cve-2025-32433</title>
    <updated>2026-10-02T18:44:29.327630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-140-07</id>
    <title>ICSA-25-140-07 — Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL (Update A)</title>
    <updated>2026-10-02T18:44:29.327653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability disclosed on the Erlang/OTP's SSH Server
 component used Schneider Electric Galaxy VS, VL, and VXL.Many vendors, including Schneider Electric, embed the Erlang/OTP's SSH Server in their offers.The Galaxy VS, Galaxy VL, Galaxy VXL products are 3-phase UPS for data centers and other business critical applications.Failure to apply the mitigation provided below may risk unauthenticated remote code execution (RCE), which could impact the monitoring capabilities of the UPS and potential UPS operation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-140-07"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-32433</id>
    <title>msrc_CVE-2025-32433 — Erlang/OTP SSH Vulnerable to Pre-Authentication RCE</title>
    <updated>2026-10-02T18:44:29.327683+00:00</updated>
    <content>msrc_CVE-2025-32433</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-32433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1461</id>
    <title>OESA-2025-1461 — erlang security update</title>
    <updated>2026-10-02T18:44:29.327697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: erlang, openEuler:22.03-LTS-SP3: erlang, openEuler:22.03-LTS-SP4: erlang, openEuler:24.03-LTS: erlang, openEuler:24.03-LTS-SP1: erlang</p>
<p>Security Fix(es):</p>
<p>Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.(CVE-2025-32433)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2025-133-05</id>
    <title>SEVD-2025-133-05 — Galaxy VS, Galaxy VL, Galaxy VXL</title>
    <updated>2026-10-02T18:44:29.327727+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability disclosed on the Erlang/OTP's SSH Server
 component used Schneider Electric Galaxy VS, VL, and VXL.Many vendors, including Schneider Electric, embed the Erlang/OTP's SSH Server in their offers.The Galaxy VS, Galaxy VL, Galaxy VXL products are 3-phase UPS for data centers and other business critical applications.Failure to apply the mitigation provided below may risk unauthenticated remote code execution (RCE), which could impact the monitoring capabilities of the UPS and potential UPS operation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2025-133-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-089022</id>
    <title>SSA-089022 — SSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3</title>
    <updated>2026-10-02T18:44:29.327746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-089022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:1356-1</id>
    <title>SUSE-SU-2025:1356-1 — Security update for erlang26</title>
    <updated>2026-10-02T18:44:29.327960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for erlang26</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:1356-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32433</id>
    <title>UBUNTU-CVE-2025-32433</title>
    <updated>2026-10-02T18:44:29.327977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang</p>
<p>Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-32433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0838</id>
    <title>WID-SEC-W-2025-0838 — Erlang/OTP SSH: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T18:44:29.328002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Erlang/OTP ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0838"/>
  </entry>
</feed>
