<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T07:04:22.103493+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-230818</id>
    <title>EUVD-2026-230818</title>
    <updated>2026-10-07T07:04:22.166769+00:00</updated>
    <content>EUVD-2026-230818</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-230818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40202</id>
    <title>fkie_cve-2022-40202</title>
    <updated>2026-10-07T07:04:22.166807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-40202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qmpg-9h7f-2x2x</id>
    <title>GHSA-qmpg-9h7f-2x2x</title>
    <updated>2026-10-07T07:04:22.166843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker could provide malicious serialized objects which, when deserialized, could activate an opcode for a backup scheduling function without authentication. This function allows the user to designate all function arguments and the file to be executed. This could allow the attacker to start any new process and achieve remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qmpg-9h7f-2x2x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-40202</id>
    <title>gsd-2022-40202</title>
    <updated>2026-10-07T07:04:22.166862+00:00</updated>
    <content>gsd-2022-40202</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-40202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-298-07</id>
    <title>ICSA-22-298-07 — Delta Electronics InfraSuite Device Master</title>
    <updated>2026-10-07T07:04:22.166874+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization. CVE-2022-41778 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization. CVE-2022-38142 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution. CVE-2022-41779 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data alr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-298-07"/>
  </entry>
</feed>
