<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:59:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-183442</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183442</link>
      <description>EUVD-2026-183442</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183442</guid>
    </item>
    <item>
      <title>fkie_cve-2021-38480</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38480</link>
      <description>&lt;p&gt;InHand Networks IR615 Router&amp;#39;s Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;InHand Networks IR615 Router&amp;#39;s Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-38480</guid>
    </item>
    <item>
      <title>GHSA-4rh6-rgjc-525r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4rh6-rgjc-525r</link>
      <description>&lt;p&gt;InHand Networks IR615 Router&amp;#39;s Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;InHand Networks IR615 Router&amp;#39;s Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4rh6-rgjc-525r</guid>
    </item>
    <item>
      <title>gsd-2021-38480</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-38480</link>
      <description>gsd-2021-38480</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-38480</guid>
    </item>
    <item>
      <title>ICSA-21-280-05 — InHand Networks IR615 Router (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-280-05</link>
      <description>&lt;p&gt;The affected product &amp;#39;s management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router &amp;#39;s management portal and could lure the administrator to perform changes.CVE-2021-38472 has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N). The vendor&amp;#39;s cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.CVE-2021-38486 has been assigned to this vulnerability. A CVSS v3 base score of 8.0 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). The affected product is vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router &amp;#39;s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.CVE-2021-38480 has been assigned to this vulnerability. A CVSS v3 base score of 9.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). The affected product has inadequate encryption strength, which may allow an attacker to intercept the communica…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product &amp;#39;s management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames the router &amp;#39;s management portal and could lure the administrator to perform changes.CVE-2021-38472 has been assigned to this vulnerability. A CVSS v3 base score of 4.7 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N). The vendor&amp;#39;s cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have full control over the product and execute code within the internal network to which the product is connected.CVE-2021-38486 has been assigned to this vulnerability. A CVSS v3 base score of 8.0 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). The affected product is vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router &amp;#39;s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.CVE-2021-38480 has been assigned to this vulnerability. A CVSS v3 base score of 9.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). The affected product has inadequate encryption strength, which may allow an attacker to intercept the communica…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-280-05</guid>
    </item>
  </channel>
</rss>
