<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:16:43.371012+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253280</id>
    <title>EUVD-2026-253280</title>
    <updated>2026-10-03T02:16:43.429250+00:00</updated>
    <content>EUVD-2026-253280</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9495</id>
    <title>fkie_cve-2025-9495</title>
    <updated>2026-10-03T02:16:43.429286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jmw7-g9jf-52hh</id>
    <title>GHSA-jmw7-g9jf-52hh</title>
    <updated>2026-10-03T02:16:43.429322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jmw7-g9jf-52hh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-266-04</id>
    <title>ICSA-25-266-04 — Viessmann Vitogate 300</title>
    <updated>2026-10-03T02:16:43.429341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vitogate 300 constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. When the server relies on client-side protection mechanisms, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-266-04"/>
  </entry>
</feed>
