<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-03464</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03464</link>
      <description>bdu:2024-03464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03464</guid>
    </item>
    <item>
      <title>EUVD-2026-5073</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5073</link>
      <description>EUVD-2026-5073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5073</guid>
    </item>
    <item>
      <title>fkie_cve-2024-32047</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32047</link>
      <description>&lt;p&gt;Hard-coded credentials for the 
CyberPower PowerPanel test server can be found in the 
production code. This might result in an attacker gaining access to the 
testing or production server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hard-coded credentials for the 
CyberPower PowerPanel test server can be found in the 
production code. This might result in an attacker gaining access to the 
testing or production server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-32047</guid>
    </item>
    <item>
      <title>GHSA-26gh-5qf3-p3q4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-26gh-5qf3-p3q4</link>
      <description>&lt;p&gt;Hard-coded credentials for the 
CyberPower PowerPanel test server can be found in the 
production code. This might result in an attacker gaining access to the 
testing or production server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hard-coded credentials for the 
CyberPower PowerPanel test server can be found in the 
production code. This might result in an attacker gaining access to the 
testing or production server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-26gh-5qf3-p3q4</guid>
    </item>
    <item>
      <title>ICSA-24-123-01 — CyberPower PowerPanel Business</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-123-01</link>
      <description>&lt;p&gt;The application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges. The application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication. A specially crafted Zip file containing path traversal characters can be imported to the server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution. Hard-coded credentials are used by the platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel Business application. Hard-coded credentials for the test server can be found in the production code. This might result in an attacker gaining access to the testing or production server. The key used to encrypt passwords stored in the database can be found in the application code, allowing the passwords to be recovered. An attacker with certain MQTT permissions can create malicious messages to all Power Panel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code. The devices Power Panel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data. Certain MQTT wild…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges. The application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication. A specially crafted Zip file containing path traversal characters can be imported to the server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution. Hard-coded credentials are used by the platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel Business application. Hard-coded credentials for the test server can be found in the production code. This might result in an attacker gaining access to the testing or production server. The key used to encrypt passwords stored in the database can be found in the application code, allowing the passwords to be recovered. An attacker with certain MQTT permissions can create malicious messages to all Power Panel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code. The devices Power Panel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data. Certain MQTT wild…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-123-01</guid>
    </item>
  </channel>
</rss>
