<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:05:39.690169+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318172</id>
    <title>EUVD-2026-318172</title>
    <updated>2026-10-07T22:05:39.694019+00:00</updated>
    <content>EUVD-2026-318172</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25107</id>
    <title>fkie_cve-2026-25107</title>
    <updated>2026-10-07T22:05:39.694049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25107"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-73h9-jvhg-453m</id>
    <title>GHSA-73h9-jvhg-453m</title>
    <updated>2026-10-07T22:05:39.694079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-73h9-jvhg-453m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000073</id>
    <title>jvndb-2026-000073</title>
    <updated>2026-10-07T22:05:39.694096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities listed below.&lt;a href='https://cwe.mitre.org/data/definitions/321.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/78.html' target='_blank'&gt;&lt;/a&gt;
&lt;a href='https://cwe.mitre.org/data/definitions/288.html' target='_blank'&gt;&lt;/a&gt;
&lt;a href='https://cwe.mitre.org/data/definitions/78.html' target='_blank'&gt;&lt;/a&gt;
&lt;a href='https://cwe.mitre.org/data/definitions/79.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/754.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/344.html' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Use of Hard-coded Cryptographic Key in creating backup of configuration files (CWE-321) - CVE-2026-25107&lt;/li&gt;&lt;li&gt;OS command injection in processing of ping_ip_addr parameter (CWE-78) - CVE-2026-35506&lt;/li&gt;&lt;li&gt;Missing authentication when accepting in specific URLs (CWE-288) - CVE-2026-40621&lt;/li&gt;&lt;li&gt;OS command injection in processing of username parameter (CWE-78) - CVE-2026-42062&lt;/li&gt;&lt;li&gt;Stored cross-site scripting due to inadequate hostname parameter handling (CWE-79) - CVE-2026-42948&lt;/li&gt;&lt;li&gt;Missing Check for language parameter (CWE-754) - CVE-2026-42950&lt;/li&gt;&lt;li&gt;Inadequate CSRF protection (CWE-344) - CVE-2026-42961&lt;/li&gt;&lt;/ul&gt;The vulnerabilities are reported from the following people, and JPCERT/CC coordinated with the developer.

CVE-2026-25107, CVE-2026-42950, CVE-2026-42961
Kentaro Ishii of GMO Cybersecur…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000073"/>
  </entry>
</feed>
