<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:03:08.748957+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-160411</id>
    <title>EUVD-2026-160411</title>
    <updated>2026-10-06T22:03:08.799289+00:00</updated>
    <content>EUVD-2026-160411</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-160411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24767</id>
    <title>fkie_cve-2024-24767</title>
    <updated>2026-10-06T22:03:08.799326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability allows attackers to get super user-level access over the server. Version 0.4.7 contains a patch for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-24767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c69x-5xmw-v44x</id>
    <title>GHSA-c69x-5xmw-v44x — CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability</title>
    <updated>2026-10-06T22:03:08.799360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/IceWhaleTech/CasaOS-UserService</p>
<p>### Summary
Here it is observed that the CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server.</p>
<p>### Details
The web application lacks control over the login attempts i.e. why attacker can use a password brute force attack to find and get full access over the.</p>
<p>### PoC
1. Capture login request in proxy tool like Burp Suite and select password field.</p>
<p>![1](https://user-images.githubusercontent.com/63414468/297156515-0272bfd7-f386-4c22-b3bd-c4dbdc1298bf.PNG)</p>
<p>2. Here I have started attack with total number of 271 password tries where the last one is the correct password and as we can see in the following image we get a **400 Bad Request** status code with the message "**Invalid Password**" and response length **769** on 1st request which was sent at **_Tue, 16 Jan 2024 18:31:32 GMT_**</p>
<p>![2](https://user-images.githubusercontent.com/63414468/297157815-c158995b-7d46-4a5a-aef9-bcbbcf596b15.png)</p>
<p>**Note**:  _We have tested this vulnerability with more than 3400 tries. We have used 271 request counts just for demo purposes._</p>
<p>3. Here the attack is completed and we can see in the following image we get **200 OK** status code with the message "**Ok**" and response length **1509** on 271st request which was sent at **_Tue, 16 Jan 2024 18:32:01 GMT_**.</p>
<p>![3](https://user-images.githubusercontent.com/63414468/297159282-3f4788b5-6217-4f32-8be6-40ac117710e3.png)</p>
<p>This means attacker can try 271 requests in 56 seconds.</p>
<p>### Impact
This…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c69x-5xmw-v44x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-24767</id>
    <title>gsd-2024-24767</title>
    <updated>2026-10-06T22:03:08.799418+00:00</updated>
    <content>gsd-2024-24767</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-24767"/>
  </entry>
</feed>
