<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:06:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253280</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253280</link>
      <description>EUVD-2026-253280</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253280</guid>
    </item>
    <item>
      <title>fkie_cve-2025-9495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9495</link>
      <description>&lt;p&gt;The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-9495</guid>
    </item>
    <item>
      <title>GHSA-jmw7-g9jf-52hh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jmw7-g9jf-52hh</link>
      <description>&lt;p&gt;The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker can reveal the hidden administration menu, giving them full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jmw7-g9jf-52hh</guid>
    </item>
    <item>
      <title>ICSA-25-266-04 — Viessmann Vitogate 300</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-266-04</link>
      <description>&lt;p&gt;Vitogate 300 constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. When the server relies on client-side protection mechanisms, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vitogate 300 constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. When the server relies on client-side protection mechanisms, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-266-04</guid>
    </item>
  </channel>
</rss>
