<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:03:00.976235+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249372</id>
    <title>EUVD-2026-249372</title>
    <updated>2026-10-03T19:03:01.022953+00:00</updated>
    <content>EUVD-2026-249372</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249372"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47872</id>
    <title>fkie_cve-2025-47872</title>
    <updated>2026-10-03T19:03:01.022990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The public-facing product registration endpoint server responds 
differently depending on whether the S/N is valid and unregistered, 
valid but already registered, or does not exist in the database. 
Combined with the fact that serial numbers are sequentially assigned, 
this allows an attacker to gain information on the product registration 
status of different S/Ns.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-47872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vp38-x48w-r4cx</id>
    <title>GHSA-vp38-x48w-r4cx</title>
    <updated>2026-10-03T19:03:01.023024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The public-facing product registration endpoint server responds 
differently depending on whether the S/N is valid and unregistered, 
valid but already registered, or does not exist in the database. 
Combined with the fact that serial numbers are sequentially assigned, 
this allows an attacker to gain information on the product registration 
status of different S/Ns.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vp38-x48w-r4cx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-219-07</id>
    <title>ICSA-25-219-07 — EG4 Electronics EG4 Inverters (Update B)</title>
    <updated>2026-10-03T19:03:01.023042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or forge critical data, including read/write operations for voltage, current, and power configuration, operational status, alarms, telemetry, system reset, or inverter control commands, potentially disrupting power generation or reconfiguring inverter settings. The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection. The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned, this allows an attacker to gain information on the product registration status of different S/Ns. The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial num…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-219-07"/>
  </entry>
</feed>
