<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:30:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330404</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330404</link>
      <description>EUVD-2026-330404</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330404</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64309</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64309</link>
      <description>&lt;p&gt;The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64309</guid>
    </item>
    <item>
      <title>GHSA-7j94-8gxx-fvqg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7j94-8gxx-fvqg</link>
      <description>&lt;p&gt;Brightpick Mission Control 
discloses device telemetry, configuration, and credential information 
via WebSocket traffic to unauthenticated users when they connect to a 
specific URL. The unauthenticated URL can be discovered through basic 
network scanning techniques.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Brightpick Mission Control 
discloses device telemetry, configuration, and credential information 
via WebSocket traffic to unauthenticated users when they connect to a 
specific URL. The unauthenticated URL can be discovered through basic 
network scanning techniques.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7j94-8gxx-fvqg</guid>
    </item>
    <item>
      <title>ICSA-25-317-04 — Brightpick Mission Control / Internal Logic Control (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-317-04</link>
      <description>&lt;p&gt;The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes. The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI&amp;#39;s documentation portal. The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes. The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI&amp;#39;s documentation portal. The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-317-04</guid>
    </item>
  </channel>
</rss>
