<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:45:25.913713+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-350652</id>
    <title>EUVD-2026-350652</title>
    <updated>2026-10-05T16:45:25.977800+00:00</updated>
    <content>EUVD-2026-350652</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-350652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66403</id>
    <title>fkie_cve-2026-66403</title>
    <updated>2026-10-05T16:45:25.977838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-66403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w22m-rfhf-hgj7</id>
    <title>GHSA-w22m-rfhf-hgj7</title>
    <updated>2026-10-05T16:45:25.977871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w22m-rfhf-hgj7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-026400</id>
    <title>jvndb-2026-026400</title>
    <updated>2026-10-05T16:45:25.977888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&lt;ul&gt;&lt;li&gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&lt;/li&gt;&lt;li&gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&lt;/li&gt;&lt;li&gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&lt;/li&gt;&lt;li&gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&lt;/li&gt;&lt;ul&gt;&lt;li&gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&lt;/li&gt;&lt;ul&gt;&lt;li&gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Weak password for root account (CWE-1391) - CVE-2026-66408&lt;/li&gt;&lt;li&gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&lt;/li&gt;&lt;li&gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&lt;/li&gt;&lt;li&gt;Dependency on vulnerable third-party component (CWE-1395)&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&lt;/li&gt;&lt;/ul&gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-026400"/>
  </entry>
</feed>
