<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:27:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-217719</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217719</link>
      <description>EUVD-2026-217719</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217719</guid>
    </item>
    <item>
      <title>fkie_cve-2025-24836</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-24836</link>
      <description>&lt;p&gt;With a specially crafted Python script, an attacker could send 
continuous startMeasurement commands over an unencrypted Bluetooth 
connection to the affected device. This would prevent the device from 
connecting to a clinician&amp;#39;s app to take patient readings and ostensibly 
flood it with requests, resulting in a denial-of-service condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;With a specially crafted Python script, an attacker could send 
continuous startMeasurement commands over an unencrypted Bluetooth 
connection to the affected device. This would prevent the device from 
connecting to a clinician&amp;#39;s app to take patient readings and ostensibly 
flood it with requests, resulting in a denial-of-service condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-24836</guid>
    </item>
    <item>
      <title>GHSA-pvvp-cjfg-4jv4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pvvp-cjfg-4jv4</link>
      <description>&lt;p&gt;With a specially crafted Python script, an attacker could send 
continuous startMeasurement commands over an unencrypted Bluetooth 
connection to the affected device. This would prevent the device from 
connecting to a clinician&amp;#39;s app to take patient readings and ostensibly 
flood it with requests, resulting in a denial-of-service condition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;With a specially crafted Python script, an attacker could send 
continuous startMeasurement commands over an unencrypted Bluetooth 
connection to the affected device. This would prevent the device from 
connecting to a clinician&amp;#39;s app to take patient readings and ostensibly 
flood it with requests, resulting in a denial-of-service condition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pvvp-cjfg-4jv4</guid>
    </item>
    <item>
      <title>ICSMA-25-044-01 — Qardio Heart Health IOS and Android Application and QardioARM A100</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-25-044-01</link>
      <description>&lt;p&gt;The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal. With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician&amp;#39;s app to take patient readings and ostensibly flood it with requests, resulting in a denial-of-service condition. An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal. With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician&amp;#39;s app to take patient readings and ostensibly flood it with requests, resulting in a denial-of-service condition. An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-25-044-01</guid>
    </item>
  </channel>
</rss>
