<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:07:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-250162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-250162</link>
      <description>EUVD-2026-250162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-250162</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53695</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53695</link>
      <description>&lt;p&gt;OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53695</guid>
    </item>
    <item>
      <title>GHSA-g6w7-rgjj-7r73</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g6w7-rgjj-7r73</link>
      <description>&lt;p&gt;OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g6w7-rgjj-7r73</guid>
    </item>
    <item>
      <title>ICSA-25-224-02 — Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-224-02</link>
      <description>&lt;p&gt;OS command injection in iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware. This is fixed in versions 6.9.3 and newer. iSTAR Ultra and Ultra SE versions 6.9.2 and prior performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Versions 6.9.3 and newer reduce the risk of this vulnerability. There is a default ‘root&amp;#39; password for iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior which can be changed through the command shell. iSTAR Ultra and Ultra SE Versions 6.9.3 and newer reduces the risk of this vulnerability.  iSTAR Ultra G2, Ultra G2 SE and Edge G2 version 6.9.3 and newer fixes this vulnerability. There is an undocumented RJ11 serial console on the iSTAR GCM (General Controller Module) which provides access to Uboot. On older firmware versions, an attacker with physical access to this console can get direct access to a shell with ‘root&amp;#39; privileges. In firmware Version 6.8.1 or newer, the console is disabled once the system has fully booted, however the console may be re-enabled due to lack of protection of the Uboot bootloader.  USB ports on the GCM board are typically used to connect an ACM (Access Control Module) board. The ACM is what reads badge data, ‘push to exit&amp;#39; signals, fire alar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OS command injection in iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior web application allows an authenticated attacker to gain even more privileged access (&amp;#39;root&amp;#39; user) to the device firmware. This is fixed in versions 6.9.3 and newer. iSTAR Ultra and Ultra SE versions 6.9.2 and prior performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Versions 6.9.3 and newer reduce the risk of this vulnerability. There is a default ‘root&amp;#39; password for iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, Edge G2 versions 6.9.2 and prior which can be changed through the command shell. iSTAR Ultra and Ultra SE Versions 6.9.3 and newer reduces the risk of this vulnerability.  iSTAR Ultra G2, Ultra G2 SE and Edge G2 version 6.9.3 and newer fixes this vulnerability. There is an undocumented RJ11 serial console on the iSTAR GCM (General Controller Module) which provides access to Uboot. On older firmware versions, an attacker with physical access to this console can get direct access to a shell with ‘root&amp;#39; privileges. In firmware Version 6.8.1 or newer, the console is disabled once the system has fully booted, however the console may be re-enabled due to lack of protection of the Uboot bootloader.  USB ports on the GCM board are typically used to connect an ACM (Access Control Module) board. The ACM is what reads badge data, ‘push to exit&amp;#39; signals, fire alar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-224-02</guid>
    </item>
  </channel>
</rss>
