<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:29:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-246363</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246363</link>
      <description>EUVD-2026-246363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246363</guid>
    </item>
    <item>
      <title>fkie_cve-2014-0760</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2014-0760</link>
      <description>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
 Modular Controller with CoDeSys and SoftMotion provide an undocumented 
access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application 
crash) via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1
 Modular Controller with CoDeSys and SoftMotion provide an undocumented 
access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application 
crash) via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2014-0760</guid>
    </item>
    <item>
      <title>GHSA-m299-9mh6-7cv5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m299-9mh6-7cv5</link>
      <description>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m299-9mh6-7cv5</guid>
    </item>
    <item>
      <title>gsd-2014-0760</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2014-0760</link>
      <description>gsd-2014-0760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2014-0760</guid>
    </item>
    <item>
      <title>ICSA-14-084-01 — Festo CECX-X-(C1/M1) Controller Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-14-084-01</link>
      <description>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001. The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service. Directory traversal vulnerability in the Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x allows remote attackers to read, overwrite, or create arbitrary files via a .. (dot dot) in a request to the TCP listener service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001. The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener service or (2) transfer files via requests to the TCP listener service. Directory traversal vulnerability in the Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x allows remote attackers to read, overwrite, or create arbitrary files via a .. (dot dot) in a request to the TCP listener service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-14-084-01</guid>
    </item>
  </channel>
</rss>
