<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:01:15.377002+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-250161</id>
    <title>EUVD-2026-250161</title>
    <updated>2026-10-02T13:01:15.433877+00:00</updated>
    <content>EUVD-2026-250161</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-250161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53696</id>
    <title>fkie_cve-2025-53696</title>
    <updated>2026-10-02T13:01:15.433913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-53696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hrv9-xx4c-jm2g</id>
    <title>GHSA-hrv9-xx4c-jm2g</title>
    <updated>2026-10-02T13:01:15.433945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hrv9-xx4c-jm2g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-224-02</id>
    <title>ICSA-25-224-02 — Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)</title>
    <updated>2026-10-02T13:01:15.433962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OS command injection in iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware. This is fixed in versions 6.9.3 and newer. iSTAR Ultra and Ultra SE versions 6.9.2 and prior performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Versions 6.9.3 and newer reduce the risk of this vulnerability. There is a default ‘root' password for iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior which can be changed through the command shell. iSTAR Ultra and Ultra SE Versions 6.9.3 and newer reduces the risk of this vulnerability.  iSTAR Ultra G2, Ultra G2 SE and Edge G2 version 6.9.3 and newer fixes this vulnerability. There is an undocumented RJ11 serial console on the iSTAR GCM (General Controller Module) which provides access to Uboot. On older firmware versions, an attacker with physical access to this console can get direct access to a shell with ‘root' privileges. In firmware Version 6.8.1 or newer, the console is disabled once the system has fully booted, however the console may be re-enabled due to lack of protection of the Uboot bootloader.  USB ports on the GCM board are typically used to connect an ACM (Access Control Module) board. The ACM is what reads badge data, ‘push to exit' signals, fire alar…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-224-02"/>
  </entry>
</feed>
