<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:28:06.049929+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-26689</id>
    <title>CVE-2025-26689</title>
    <updated>2026-10-07T22:28:06.053952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Inaba Denki Sangyo Co., Ltd. CHOCO TEI WATCHER mini (IB-MCT001)</p>
<p>Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-26689"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-084-04</id>
    <title>ICSA-25-084-04 — Inaba Denki Sangyo CHOCO TEI WATCHER mini</title>
    <updated>2026-10-07T22:28:06.054048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product is vulnerable to a use of client-side authentication vulnerability, which may allow an attacker to obtain the product's login password without authentication. An attacker who can access the microSD card used on the product may obtain the product's login password. The affected product is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. If a remote attacker sends a specially crafted HTTP request to the product, the product's data may be obtained or deleted, and/or the product's settings may be altered.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-084-04"/>
  </entry>
</feed>
