<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:56:54.473615+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361871</id>
    <title>EUVD-2026-361871</title>
    <updated>2026-10-02T14:56:54.530929+00:00</updated>
    <content>EUVD-2026-361871</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69658</id>
    <title>fkie_cve-2026-69658</title>
    <updated>2026-10-02T14:56:54.530972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MQTT credentials and control traffic are transmitted in cleartext, 
exposing sensitive information to network-level attackers. This may 
enable unauthorized device impersonation and disruption of messaging 
functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vcvc-jqq8-cgj4</id>
    <title>GHSA-vcvc-jqq8-cgj4</title>
    <updated>2026-10-02T14:56:54.531016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MQTT credentials and control traffic are transmitted in cleartext, 
exposing sensitive information to network-level attackers. This may 
enable unauthorized device impersonation and disruption of messaging 
functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vcvc-jqq8-cgj4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-237-06</id>
    <title>ICSA-26-237-06 — Ebyte NE2-D11</title>
    <updated>2026-10-02T14:56:54.531044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality. Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access. Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-237-06"/>
  </entry>
</feed>
