<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:03:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265121</link>
      <description>EUVD-2026-265121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265121</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64305</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64305</link>
      <description>&lt;p&gt;MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64305</guid>
    </item>
    <item>
      <title>GHSA-9crg-j5q8-hwv3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9crg-j5q8-hwv3</link>
      <description>&lt;p&gt;MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9crg-j5q8-hwv3</guid>
    </item>
    <item>
      <title>ICSA-26-006-01 — Columbia Weather Systems MicroServer</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-006-01</link>
      <description>&lt;p&gt;An unused function in the MicroServer can start a reverse ssh connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device. The MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal. An unused webshell in the MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to the MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unused function in the MicroServer can start a reverse ssh connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device. The MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal. An unused webshell in the MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to the MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-006-01</guid>
    </item>
  </channel>
</rss>
