<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:41:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253908</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253908</link>
      <description>EUVD-2026-253908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253908</guid>
    </item>
    <item>
      <title>fkie_cve-2025-24525</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-24525</link>
      <description>&lt;p&gt;Keysight Ixia Vision has an issue with hardcoded cryptographic material 
which may allow an attacker to intercept or decrypt payloads sent to the
 device via API calls or user authentication if the end user does not 
replace the TLS certificate that shipped with the device. Remediation is
 available in Version 6.9.1, released on September 23, 2025.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Keysight Ixia Vision has an issue with hardcoded cryptographic material 
which may allow an attacker to intercept or decrypt payloads sent to the
 device via API calls or user authentication if the end user does not 
replace the TLS certificate that shipped with the device. Remediation is
 available in Version 6.9.1, released on September 23, 2025.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-24525</guid>
    </item>
    <item>
      <title>GHSA-vwrv-83mx-fgfh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vwrv-83mx-fgfh</link>
      <description>&lt;p&gt;Keysight Ixia Vision has an issue with hardcoded cryptographic material 
which may allow an attacker to intercept or decrypt payloads sent to the
 device via API calls or user authentication if the end user does not 
replace the TLS certificate that shipped with the device. Remediation is
 available in Version 6.9.1, released on September 23, 2025.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Keysight Ixia Vision has an issue with hardcoded cryptographic material 
which may allow an attacker to intercept or decrypt payloads sent to the
 device via API calls or user authentication if the end user does not 
replace the TLS certificate that shipped with the device. Remediation is
 available in Version 6.9.1, released on September 23, 2025.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vwrv-83mx-fgfh</guid>
    </item>
    <item>
      <title>ICSA-25-063-02 — Keysight Ixia Vision Product Family (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-063-02</link>
      <description>&lt;p&gt;Path traversal may allow remote code execution using a privileged account (requires a device admin account, which cannot be performed by a regular user). In combination with the &amp;#39;Upload&amp;#39; functionality this vulnerability could be used to execute an arbitrary script or possibly upload a binary. Remediation is available in Version 6.7.0 released on October 20, 2024. External XML entity injection allows the arbitrary download of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Path traversal may lead to the arbitrary download of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Path traversal may lead to the arbitrary deletion of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Path traversal may allow remote code execution using a privileged account (requires a device admin account, which cannot be performed by a regular user). In combination with the &amp;#39;Upload&amp;#39; functionality this vulnerability could be used to execute an arbitrary script or possibly upload a binary. Remediation is available in Version 6.7.0 released on October 20, 2024. External XML entity injection allows the arbitrary download of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Path traversal may lead to the arbitrary download of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Path traversal may lead to the arbitrary deletion of files. The score without the least privilege principle violation is calculated below. In combination with other issues, it may facilitate the further compromise of the device. Remediation is available in Version 6.8.0, released on March 1, 2025. Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-063-02</guid>
    </item>
  </channel>
</rss>
