<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:52:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-248503</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248503</link>
      <description>EUVD-2026-248503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248503</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52918</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52918</link>
      <description>&lt;p&gt;Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52918</guid>
    </item>
    <item>
      <title>GHSA-pwj2-p9vr-j8jr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pwj2-p9vr-j8jr</link>
      <description>&lt;p&gt;Yealink YMCS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yealink YMCS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pwj2-p9vr-j8jr</guid>
    </item>
    <item>
      <title>ICSA-25-219-08 — Yealink IP Phones and RPS (Redirect and Provisioning Service)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-219-08</link>
      <description>&lt;p&gt;The affected products lack serial number verification attempt limits, enabling brute-force enumeration (last five digits). The affected products lack rate limiting, potentially enabling information disclosure via excessive requests. The affected products fail to enforce access restrictions on OpenAPIs for frozen enterprise accounts, allowing unauthorized access to deactivated interfaces. The certificate upload function in the affected products does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products lack serial number verification attempt limits, enabling brute-force enumeration (last five digits). The affected products lack rate limiting, potentially enabling information disclosure via excessive requests. The affected products fail to enforce access restrictions on OpenAPIs for frozen enterprise accounts, allowing unauthorized access to deactivated interfaces. The certificate upload function in the affected products does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-219-08</guid>
    </item>
  </channel>
</rss>
