<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:10:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15630</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15630</link>
      <description>bdu:2025-15630</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15630</guid>
    </item>
    <item>
      <title>cnvd-2026-00018</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-00018</link>
      <description>cnvd-2026-00018</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-00018</guid>
    </item>
    <item>
      <title>EUVD-2026-265534</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265534</link>
      <description>EUVD-2026-265534</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265534</guid>
    </item>
    <item>
      <title>fkie_cve-2024-56840</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-56840</link>
      <description>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.17.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-56840</guid>
    </item>
    <item>
      <title>GHSA-7jwp-5g38-77m9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7jwp-5g38-77m9</link>
      <description>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX II family (All versions &amp;lt; V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX II family (All versions &amp;lt; V2.17.0). Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7jwp-5g38-77m9</guid>
    </item>
    <item>
      <title>ICSA-26-015-11 — Siemens RUGGEDCOM ROX II</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-015-11</link>
      <description>&lt;p&gt;The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shell and gain root access on the affected system. The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user. Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user. Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shell and gain root access on the affected system. The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user. Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user. Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-015-11</guid>
    </item>
    <item>
      <title>SSA-912274 — SSA-912274: Multiple Vulnerabilities in RUGGEDCOM ROX Before V2.17</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-912274</link>
      <description>&lt;p&gt;The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shell and gain root access on the affected system. The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user. Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user. Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DHCP Server configuration file of the affected products is subject to code injection. An attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. During the Dynamic DNS configuration of the affected product it is possible to inject additional configuration parameters. Under certain circumstances, an attacker could leverage this vulnerability to spawn a reverse shell and gain root access on the affected system. Due to the insufficient validation during the installation and load of certain configuration files of the affected device, an attacker could spawn a reverse shell and gain root access on the affected system. The SCEP client available in the affected device for secure certificate enrollment lacks validation of multiple fields. An attacker could leverage this scenario to execute arbitrary code as root user. Code injection can be achieved when the affected device is using VRF (Virtual Routing and Forwarding). An attacker could leverage this scenario to execute arbitrary code as root user. Under certain conditions, IPsec may allow code injection in the affected device. An attacker could leverage this scenario to execute arbitrary code as root user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-912274</guid>
    </item>
  </channel>
</rss>
