<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:21:33.083498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-22323</id>
    <title>CVE-2026-22323 — Cross‑Site Request Forgery in Link Aggregation Configuration</title>
    <updated>2026-10-07T01:21:33.098668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Phoenix Contact FL SWITCH 2005, Phoenix Contact FL SWITCH 2008, Phoenix Contact FL SWITCH 2016, Phoenix Contact FL SWITCH 2105, Phoenix Contact FL SWITCH 2108, Phoenix Contact FL SWITCH 2116, Phoenix Contact FL SWITCH 2204-2TC-2SFX, Phoenix Contact FL SWITCH 2205, Phoenix Contact FL SWITCH 2206-2FX, Phoenix Contact FL SWITCH 2206-2FX SM and 67 more</p>
<p>A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the device will automatically recover without external intervention.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-22323"/>
  </entry>
</feed>
