<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:58:18 +0000</lastBuildDate>
    <item>
      <title>BSI-2026-0001 — Unauthorized access affects VibroLine and AvibiaLine devices</title>
      <link>https://cve.radiocsirt.org/vuln/bsi-2026-0001</link>
      <description>&lt;p&gt;The ethernet and USB connections are not properly isolated allowing an attacker to configure and reset the device if configuration via ethernet is enabled and there is at least one legitimately authenticated connection active at the time of the attack. Resetting the device passwords using an invalid reset file causes a full device reset if the device is connected via USB. The function to switch between multiple configuration presets via HTTP does not require authentication. An attacker with access to the network could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via Modbus (TCP) does not require authentication. An attacker with access to the network could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via Modbus (RS485) does not require authentication. An attacker with access to the RS485 bus could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via CAN does not require authentication. An attacker with access to the RS485 bus could use this functionality to disrupt normal operations if there is more than one configuration preset. Devices are shipped without a password by default and setting a password is not enforced.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ethernet and USB connections are not properly isolated allowing an attacker to configure and reset the device if configuration via ethernet is enabled and there is at least one legitimately authenticated connection active at the time of the attack. Resetting the device passwords using an invalid reset file causes a full device reset if the device is connected via USB. The function to switch between multiple configuration presets via HTTP does not require authentication. An attacker with access to the network could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via Modbus (TCP) does not require authentication. An attacker with access to the network could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via Modbus (RS485) does not require authentication. An attacker with access to the RS485 bus could use this functionality to disrupt normal operations if there is more than one configuration preset. The function to switch between multiple configuration presets via CAN does not require authentication. An attacker with access to the RS485 bus could use this functionality to disrupt normal operations if there is more than one configuration preset. Devices are shipped without a password by default and setting a password is not enforced.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bsi-2026-0001</guid>
    </item>
    <item>
      <title>EUVD-2026-267066</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267066</link>
      <description>EUVD-2026-267066</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267066</guid>
    </item>
    <item>
      <title>fkie_cve-2022-50978</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-50978</link>
      <description>&lt;p&gt;An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-50978</guid>
    </item>
    <item>
      <title>GHSA-vcc2-8qcw-j2m8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vcc2-8qcw-j2m8</link>
      <description>&lt;p&gt;An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vcc2-8qcw-j2m8</guid>
    </item>
  </channel>
</rss>
