<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:06:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-27612</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-27612</link>
      <description>EUVD-2026-27612</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-27612</guid>
    </item>
    <item>
      <title>fkie_cve-2021-31698</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31698</link>
      <description>&lt;p&gt;Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-31698</guid>
    </item>
    <item>
      <title>GHSA-7r3r-jp3h-r9vx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7r3r-jp3h-r9vx</link>
      <description>&lt;p&gt;Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7r3r-jp3h-r9vx</guid>
    </item>
    <item>
      <title>gsd-2021-31698</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-31698</link>
      <description>gsd-2021-31698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-31698</guid>
    </item>
    <item>
      <title>jvndb-2026-026400</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026400</link>
      <description>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;telnet server remains enabled (CWE-489) - CVE-2026-66405&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing server certificate verification in wget command (CWE-295) - CVE-2026-66406&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected product.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Use of a Broken or Risky Cryptographic Algorithm in WebSocket communication authentication (CWE-327) - CVE-2026-66407&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;A man-in-the-middle attack could allow an attacker to analyze the WebSocket private key.&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Weak password for root account (CWE-1391) - CVE-2026-66408&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Weak password for Wi-Fi hotspot network (CWE-1391) - CVE-2026-66409&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper server certificate verification in the smartphone app (CWE-295) - CVE-2026-66410&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Dependency on vulnerable third-party component (CWE-1395)&amp;lt;/li&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Known vulnerability in Quectel EG25-G device (CVE-2021-31698)&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&amp;lt;li&amp;gt;Incorrect implementation of authentication algorithm in Websocket communications (CWE-303) - CVE-2026-66411&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;Hellohas Robotics Inc. reported and coordinated these vulnerabilities with ECOVACS ROBOT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026400</guid>
    </item>
  </channel>
</rss>
