<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:27:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-02901</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02901</link>
      <description>bdu:2023-02901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02901</guid>
    </item>
    <item>
      <title>certfr-2021-avi-953 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-953</link>
      <description>certfr-2021-avi-953</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-953</guid>
    </item>
    <item>
      <title>EUVD-2026-23181</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-23181</link>
      <description>EUVD-2026-23181</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-23181</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22822</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22822</link>
      <description>&lt;p&gt;A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22822</guid>
    </item>
    <item>
      <title>GHSA-qm5p-m3pg-gj6g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qm5p-m3pg-gj6g</link>
      <description>&lt;p&gt;A CWE-79 Improper Neutralization of Input During Web Page Generation (?Cross-site Scripting?) vulnerability exists that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-79 Improper Neutralization of Input During Web Page Generation (?Cross-site Scripting?) vulnerability exists that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qm5p-m3pg-gj6g</guid>
    </item>
    <item>
      <title>gsd-2021-22822</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22822</link>
      <description>gsd-2021-22822</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22822</guid>
    </item>
    <item>
      <title>SEVD-2021-348-02 — EVlink City / Parking / Smart Wallbox Charging Stations</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-348-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EVlink City, Parking, and Smart Wallbox products.&#13;
The EVlink products are electric vehicle (EV) charging stations for private properties, semi-public car parks and on-street charging.&#13;
These vulnerabilities can be exploited by obtaining physical access either to the charging station’s internal communication port, which requires disassembling the charging station enclosure, or, in the case of a connected station, to the network of the charging station’s supervision system. The risk is further elevated when the connected stations are accessible over the internet and have insufficient network security measures.&#13;
Customers should immediately apply the available remediations. Failure to do so may risk potential unauthorized access to the charging station’s web server, which could lead to tampering and compromise of the charging station’s settings and accounts. Such tampering could lead to things like denial of service attacks, which could result in unauthorized use of the charging station, service interruptions, failure to send charging data records to the supervision system and the modification and disclosure of the charging station’s configuration.&#13;
In addition to applying the available remediations to limit the risk of a connected charging station being compromised, Schneider Electric recommends that customers follow and apply network security best practices and ensure that the charging stations are not accessible…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EVlink City, Parking, and Smart Wallbox products.&#13;
The EVlink products are electric vehicle (EV) charging stations for private properties, semi-public car parks and on-street charging.&#13;
These vulnerabilities can be exploited by obtaining physical access either to the charging station’s internal communication port, which requires disassembling the charging station enclosure, or, in the case of a connected station, to the network of the charging station’s supervision system. The risk is further elevated when the connected stations are accessible over the internet and have insufficient network security measures.&#13;
Customers should immediately apply the available remediations. Failure to do so may risk potential unauthorized access to the charging station’s web server, which could lead to tampering and compromise of the charging station’s settings and accounts. Such tampering could lead to things like denial of service attacks, which could result in unauthorized use of the charging station, service interruptions, failure to send charging data records to the supervision system and the modification and disclosure of the charging station’s configuration.&#13;
In addition to applying the available remediations to limit the risk of a connected charging station being compromised, Schneider Electric recommends that customers follow and apply network security best practices and ensure that the charging stations are not accessible…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-348-02</guid>
    </item>
  </channel>
</rss>
