<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:39:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276927</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276927</link>
      <description>EUVD-2026-276927</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276927</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32666</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32666</link>
      <description>&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32666</guid>
    </item>
    <item>
      <title>GHSA-2v87-3m5p-q6cw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2v87-3m5p-q6cw</link>
      <description>&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2v87-3m5p-q6cw</guid>
    </item>
    <item>
      <title>ICSA-26-078-08 — Automated Logic WebCTRL Premium Server</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-078-08</link>
      <description>&lt;p&gt;Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software. WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate. Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark&amp;#39;s BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software. WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate. Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark&amp;#39;s BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-078-08</guid>
    </item>
  </channel>
</rss>
