<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:02:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04969</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04969</link>
      <description>bdu:2025-04969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04969</guid>
    </item>
    <item>
      <title>EUVD-2026-226261</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226261</link>
      <description>EUVD-2026-226261</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226261</guid>
    </item>
    <item>
      <title>fkie_cve-2025-26689</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-26689</link>
      <description>&lt;p&gt;Direct request (&amp;#39;Forced Browsing&amp;#39;) issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Direct request (&amp;#39;Forced Browsing&amp;#39;) issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-26689</guid>
    </item>
    <item>
      <title>GHSA-3p6f-jvp3-w6pm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3p6f-jvp3-w6pm</link>
      <description>&lt;p&gt;Direct request (&amp;#39;Forced Browsing&amp;#39;) issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Direct request (&amp;#39;Forced Browsing&amp;#39;) issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3p6f-jvp3-w6pm</guid>
    </item>
    <item>
      <title>ICSA-25-084-04 — Inaba Denki Sangyo CHOCO TEI WATCHER mini</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-084-04</link>
      <description>&lt;p&gt;The affected product is vulnerable to a use of client-side authentication vulnerability, which may allow an attacker to obtain the product&amp;#39;s login password without authentication. An attacker who can access the microSD card used on the product may obtain the product&amp;#39;s login password. The affected product is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. If a remote attacker sends a specially crafted HTTP request to the product, the product&amp;#39;s data may be obtained or deleted, and/or the product&amp;#39;s settings may be altered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product is vulnerable to a use of client-side authentication vulnerability, which may allow an attacker to obtain the product&amp;#39;s login password without authentication. An attacker who can access the microSD card used on the product may obtain the product&amp;#39;s login password. The affected product is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. If a remote attacker sends a specially crafted HTTP request to the product, the product&amp;#39;s data may be obtained or deleted, and/or the product&amp;#39;s settings may be altered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-084-04</guid>
    </item>
    <item>
      <title>jvndb-2025-002592</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-002592</link>
      <description>&lt;p&gt;CHOCO TEI WATCHER mini provided by Inaba Denki Sangyo Co., Ltd. contains multiple vulnerabilities listed below.&#13;
&#13;
* Use of client-side authentication (CWE-603) - CVE-2025-24517&#13;
* Storing passwords in a recoverable format (CWE-257) - CVE-2025-24852&#13;
* Weak password requirements (CWE-521) - CVE-2025-25211&#13;
* Forced browsing (CWE-425) - CVE-2025-26689&#13;
&#13;
Andrea Palanca of Nozomi Networks reported these vulnerabilities to the developer and CISA ICS.&#13;
JPCERT/CC coordinated with the reporter, CISA ICS, and the developer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CHOCO TEI WATCHER mini provided by Inaba Denki Sangyo Co., Ltd. contains multiple vulnerabilities listed below.&#13;
&#13;
* Use of client-side authentication (CWE-603) - CVE-2025-24517&#13;
* Storing passwords in a recoverable format (CWE-257) - CVE-2025-24852&#13;
* Weak password requirements (CWE-521) - CVE-2025-25211&#13;
* Forced browsing (CWE-425) - CVE-2025-26689&#13;
&#13;
Andrea Palanca of Nozomi Networks reported these vulnerabilities to the developer and CISA ICS.&#13;
JPCERT/CC coordinated with the reporter, CISA ICS, and the developer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-002592</guid>
    </item>
  </channel>
</rss>
