<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:51:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-217480</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217480</link>
      <description>EUVD-2026-217480</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217480</guid>
    </item>
    <item>
      <title>fkie_cve-2024-5410</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5410</link>
      <description>&lt;p&gt;Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-5410</guid>
    </item>
    <item>
      <title>ICSA-25-044-15 — ORing IAP-420</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-044-15</link>
      <description>&lt;p&gt;A stored cross-site scripting can be triggered by placing JavaScript code into the SSID input field of the web interface. An attacker could exploit this vulnerability by luring an authenticated user to visit a malicious website. The filename parameter of a configuration file upload is prone to a command injection vulnerability. This vulnerability can only be exploited if a user is authenticated to the web interface. An attacker could invoke commands and gain full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored cross-site scripting can be triggered by placing JavaScript code into the SSID input field of the web interface. An attacker could exploit this vulnerability by luring an authenticated user to visit a malicious website. The filename parameter of a configuration file upload is prone to a command injection vulnerability. This vulnerability can only be exploited if a user is authenticated to the web interface. An attacker could invoke commands and gain full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-044-15</guid>
    </item>
  </channel>
</rss>
