<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:12:09 +0000</lastBuildDate>
    <item>
      <title>cnvd-2019-47029</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-47029</link>
      <description>cnvd-2019-47029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-47029</guid>
    </item>
    <item>
      <title>EUVD-2026-162442</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-162442</link>
      <description>EUVD-2026-162442</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-162442</guid>
    </item>
    <item>
      <title>fkie_cve-2019-14929</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-14929</link>
      <description>&lt;p&gt;An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-14929</guid>
    </item>
    <item>
      <title>GHSA-9r4h-2cr5-xvhv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9r4h-2cr5-xvhv</link>
      <description>&lt;p&gt;An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9r4h-2cr5-xvhv</guid>
    </item>
    <item>
      <title>gsd-2019-14929</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-14929</link>
      <description>gsd-2019-14929</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-14929</guid>
    </item>
    <item>
      <title>ICSA-21-252-03 — Mitsubishi Electric Europe B.V. smartRTU and INEA ME-RTU</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-252-03</link>
      <description>&lt;p&gt;The affected product allows an attacker to execute arbitrary commands due to the passing of unsafe user supplied data to the system shell.CVE-2019-14931 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). It is possible to download the affected product &amp;#39;s configuration file, which contains sensitive data, through the URL.CVE-2019-14927 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The affected product &amp;#39;s web configuration software allows an authenticated user to inject malicious data into the application that can then be executed in a victim &amp;#39;s browser, allowing stored cross-site scripting.CVE-2019-14928 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). Hard-coded SSH keys have been identified in the affected product &amp;#39;s firmware. As the secure keys cannot be regenerated by a user and are not regenerated on firmware updates, all deployed affected products utilize the same SSH keys.CVE-2019-14926 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The affected products contain undocumented user accounts with hard-coded password credentials. An attacker could exploi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product allows an attacker to execute arbitrary commands due to the passing of unsafe user supplied data to the system shell.CVE-2019-14931 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). It is possible to download the affected product &amp;#39;s configuration file, which contains sensitive data, through the URL.CVE-2019-14927 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The affected product &amp;#39;s web configuration software allows an authenticated user to inject malicious data into the application that can then be executed in a victim &amp;#39;s browser, allowing stored cross-site scripting.CVE-2019-14928 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). Hard-coded SSH keys have been identified in the affected product &amp;#39;s firmware. As the secure keys cannot be regenerated by a user and are not regenerated on firmware updates, all deployed affected products utilize the same SSH keys.CVE-2019-14926 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The affected products contain undocumented user accounts with hard-coded password credentials. An attacker could exploi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-252-03</guid>
    </item>
  </channel>
</rss>
