<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:52:56.658475+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248503</id>
    <title>EUVD-2026-248503</title>
    <updated>2026-10-06T19:52:56.662087+00:00</updated>
    <content>EUVD-2026-248503</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52918</id>
    <title>fkie_cve-2025-52918</title>
    <updated>2026-10-06T19:52:56.662119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pwj2-p9vr-j8jr</id>
    <title>GHSA-pwj2-p9vr-j8jr</title>
    <updated>2026-10-06T19:52:56.662150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Yealink YMCS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pwj2-p9vr-j8jr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-219-08</id>
    <title>ICSA-25-219-08 — Yealink IP Phones and RPS (Redirect and Provisioning Service)</title>
    <updated>2026-10-06T19:52:56.662167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected products lack serial number verification attempt limits, enabling brute-force enumeration (last five digits). The affected products lack rate limiting, potentially enabling information disclosure via excessive requests. The affected products fail to enforce access restrictions on OpenAPIs for frozen enterprise accounts, allowing unauthorized access to deactivated interfaces. The certificate upload function in the affected products does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-219-08"/>
  </entry>
</feed>
