<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 03:48:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04253</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04253</link>
      <description>bdu:2022-04253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04253</guid>
    </item>
    <item>
      <title>certfr-2022-avi-546 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-546</link>
      <description>certfr-2022-avi-546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-546</guid>
    </item>
    <item>
      <title>cnvd-2023-40178</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-40178</link>
      <description>cnvd-2023-40178</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-40178</guid>
    </item>
    <item>
      <title>EUVD-2026-213792</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-213792</link>
      <description>EUVD-2026-213792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-213792</guid>
    </item>
    <item>
      <title>fkie_cve-2022-32516</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32516</link>
      <description>&lt;p&gt;A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-32516</guid>
    </item>
    <item>
      <title>GHSA-gqgc-w6w9-6h7c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gqgc-w6w9-6h7c</link>
      <description>&lt;p&gt;A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gqgc-w6w9-6h7c</guid>
    </item>
    <item>
      <title>gsd-2022-32516</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-32516</link>
      <description>gsd-2022-32516</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-32516</guid>
    </item>
    <item>
      <title>SEVD-2022-165-03 — Conext™ Combox</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2022-165-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Conext™ ComBox product which was discontinued in January 2020 and is no longer in support.&#13;
The Conext™ ComBox is a communication and monitoring device for installers and operators of Conext solar systems. It features an integrated web server, enabling graphical displays of system daily, monthly and lifetime energy data to be viewed using a simple web browser or Android tablet device.&#13;
Failure to apply the mitigations provided below may risk Clickjacking, Rate Limiting &amp;amp; Cross-Site Request Forgery attacks. An attacker who successfully exploits one or more of these vulnerabilities could trick the product user/admin into performing unintended actions that may lead to taking over their account or manipulating the station settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Conext™ ComBox product which was discontinued in January 2020 and is no longer in support.&#13;
The Conext™ ComBox is a communication and monitoring device for installers and operators of Conext solar systems. It features an integrated web server, enabling graphical displays of system daily, monthly and lifetime energy data to be viewed using a simple web browser or Android tablet device.&#13;
Failure to apply the mitigations provided below may risk Clickjacking, Rate Limiting &amp;amp; Cross-Site Request Forgery attacks. An attacker who successfully exploits one or more of these vulnerabilities could trick the product user/admin into performing unintended actions that may lead to taking over their account or manipulating the station settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2022-165-03</guid>
    </item>
  </channel>
</rss>
