<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:11:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-254373</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-254373</link>
      <description>EUVD-2026-254373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-254373</guid>
    </item>
    <item>
      <title>fkie_cve-2024-5411</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5411</link>
      <description>&lt;p&gt;Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-5411</guid>
    </item>
    <item>
      <title>ICSA-25-044-15 — ORing IAP-420</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-044-15</link>
      <description>&lt;p&gt;A stored cross-site scripting can be triggered by placing JavaScript code into the SSID input field of the web interface. An attacker could exploit this vulnerability by luring an authenticated user to visit a malicious website. The filename parameter of a configuration file upload is prone to a command injection vulnerability. This vulnerability can only be exploited if a user is authenticated to the web interface. An attacker could invoke commands and gain full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored cross-site scripting can be triggered by placing JavaScript code into the SSID input field of the web interface. An attacker could exploit this vulnerability by luring an authenticated user to visit a malicious website. The filename parameter of a configuration file upload is prone to a command injection vulnerability. This vulnerability can only be exploited if a user is authenticated to the web interface. An attacker could invoke commands and gain full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-044-15</guid>
    </item>
  </channel>
</rss>
