<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:59:36 +0000</lastBuildDate>
    <item>
      <title>4TZ00000006007 — ALS-mini-S4/S8 IP Missing Authentication Vulnerability and its Mitigations</title>
      <link>https://cve.radiocsirt.org/vuln/4tz00000006007</link>
      <description>&lt;p&gt;ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/4tz00000006007</guid>
    </item>
    <item>
      <title>bdu:2025-13969</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13969</link>
      <description>bdu:2025-13969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13969</guid>
    </item>
    <item>
      <title>EUVD-2026-256758</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256758</link>
      <description>EUVD-2026-256758</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256758</guid>
    </item>
    <item>
      <title>fkie_cve-2025-9574</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9574</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .&lt;/p&gt;
&lt;p&gt;All firmware versions with the Serial Number from 2000 to 5166&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .&lt;/p&gt;
&lt;p&gt;All firmware versions with the Serial Number from 2000 to 5166&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-9574</guid>
    </item>
    <item>
      <title>GHSA-22jr-jqv2-c6r8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22jr-jqv2-c6r8</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .&lt;/p&gt;
&lt;p&gt;All firmware versions with the Serial Number from 2000 to 5166&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .&lt;/p&gt;
&lt;p&gt;All firmware versions with the Serial Number from 2000 to 5166&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22jr-jqv2-c6r8</guid>
    </item>
    <item>
      <title>ICSA-25-296-02 — ASKI Energy ALS-Mini-S8 and ALS-Mini-S4</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-296-02</link>
      <description>&lt;p&gt;A critical severity missing authentication vulnerability exists in the embedded web server of the ALS-mini-S4/S8 IP controllers. There is a lack of authentication functionality. Specifically, an attacker can read and modify product configuration parameters without being authenticated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A critical severity missing authentication vulnerability exists in the embedded web server of the ALS-mini-S4/S8 IP controllers. There is a lack of authentication functionality. Specifically, an attacker can read and modify product configuration parameters without being authenticated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-296-02</guid>
    </item>
  </channel>
</rss>
