<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 17:18:20 +0000</lastBuildDate>
    <item>
      <title>certfr-2019-avi-598 — De multiples vulnérabilités ont été découvertes dans Moxa AWK-3121.
Certaines d'entre elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-598</link>
      <description>certfr-2019-avi-598</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-598</guid>
    </item>
    <item>
      <title>cnvd-2019-17007</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-17007</link>
      <description>cnvd-2019-17007</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-17007</guid>
    </item>
    <item>
      <title>EUVD-2026-64770</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-64770</link>
      <description>EUVD-2026-64770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-64770</guid>
    </item>
    <item>
      <title>fkie_cve-2018-10700</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10700</link>
      <description>&lt;p&gt;An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter &amp;#34;iw_board_deviceName&amp;#34; is susceptible to this injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter &amp;#34;iw_board_deviceName&amp;#34; is susceptible to this injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-10700</guid>
    </item>
    <item>
      <title>GHSA-vq47-4ffr-fmjh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vq47-4ffr-fmjh</link>
      <description>&lt;p&gt;An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter &amp;#34;iw_board_deviceName&amp;#34; is susceptible to this injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to execute XSS by injecting an XSS payload. The POST parameter &amp;#34;iw_board_deviceName&amp;#34; is susceptible to this injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vq47-4ffr-fmjh</guid>
    </item>
    <item>
      <title>gsd-2018-10700</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-10700</link>
      <description>gsd-2018-10700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-10700</guid>
    </item>
    <item>
      <title>ICSA-19-337-02 — Moxa AWK-3121</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-337-02</link>
      <description>&lt;p&gt;The device uses HTTP traffic by default allowing insecure communication to the web server, which could allow an attacker to compromise sensitive data such as credentials.CVE-2018-10690 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). An attacker can navigate to a URL and download the system log without authentication, which may allow access to sensitive information.CVE-2018-10691 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). A cross-site scripting attack allows access to session cookies, which may allow an attacker to login into the device.CVE-2018-10692 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An unauthorized user may execute network troubleshooting commands to cause a buffer overflow condition, which may allow the attacker to execute commands on the device.CVE-2018-10693 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The Wi-Fi connection used to set up the device is not encrypted by default, which may allow an attacker to capture sensitive data.CVE-2018-10694 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The device uses HTTP traffic by default allowing insecure communication to the web server, which could allow an attacker to compromise sensitive data such as credentials.CVE-2018-10690 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). An attacker can navigate to a URL and download the system log without authentication, which may allow access to sensitive information.CVE-2018-10691 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). A cross-site scripting attack allows access to session cookies, which may allow an attacker to login into the device.CVE-2018-10692 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An unauthorized user may execute network troubleshooting commands to cause a buffer overflow condition, which may allow the attacker to execute commands on the device.CVE-2018-10693 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The Wi-Fi connection used to set up the device is not encrypted by default, which may allow an attacker to capture sensitive data.CVE-2018-10694 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-337-02</guid>
    </item>
  </channel>
</rss>
