<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:42:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-211159</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211159</link>
      <description>EUVD-2026-211159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211159</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26155</link>
      <description>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
expose clear text credentials in the web portal. An attacker can access 
the ETIC RAS web portal and view the HTML code, which is configured to 
be hidden, thus allowing a connection to the ETIC RAS ssh server, which 
could enable an attacker to perform actions on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
expose clear text credentials in the web portal. An attacker can access 
the ETIC RAS web portal and view the HTML code, which is configured to 
be hidden, thus allowing a connection to the ETIC RAS ssh server, which 
could enable an attacker to perform actions on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26155</guid>
    </item>
    <item>
      <title>GHSA-39g8-rv9x-hwgr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-39g8-rv9x-hwgr</link>
      <description>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
expose clear text credentials in the web portal. An attacker can access 
the ETIC RAS web portal and view the HTML code, which is configured to 
be hidden, thus allowing a connection to the ETIC RAS ssh server, which 
could enable an attacker to perform actions on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
expose clear text credentials in the web portal. An attacker can access 
the ETIC RAS web portal and view the HTML code, which is configured to 
be hidden, thus allowing a connection to the ETIC RAS ssh server, which 
could enable an attacker to perform actions on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-39g8-rv9x-hwgr</guid>
    </item>
    <item>
      <title>gsd-2024-26155</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26155</link>
      <description>gsd-2024-26155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26155</guid>
    </item>
    <item>
      <title>ICSA-22-307-01 — ETIC Telecom Remote Access Server (RAS) (Update B)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-307-01</link>
      <description>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior&amp;#39;s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.  All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior&amp;#39;s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more. All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device. All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client. All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get_view method under view parameter. The ETIC RAS web serv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior&amp;#39;s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.  All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior&amp;#39;s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more. All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device. All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and reflects the input in its response to the client. All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in get_view method under view parameter. The ETIC RAS web serv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-307-01</guid>
    </item>
  </channel>
</rss>
