<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:55:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-361122</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361122</link>
      <description>EUVD-2026-361122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361122</guid>
    </item>
    <item>
      <title>fkie_cve-2026-75813</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-75813</link>
      <description>&lt;p&gt;Certain configuration endpoints may lack proper server-side 
authorization checks, allowing unauthorized users to access or modify 
sensitive device settings. This could result in full compromise of 
device functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Certain configuration endpoints may lack proper server-side 
authorization checks, allowing unauthorized users to access or modify 
sensitive device settings. This could result in full compromise of 
device functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-75813</guid>
    </item>
    <item>
      <title>GHSA-7mpm-96ch-vg98</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7mpm-96ch-vg98</link>
      <description>&lt;p&gt;Certain configuration endpoints may lack proper server-side 
authorization checks, allowing unauthorized users to access or modify 
sensitive device settings. This could result in full compromise of 
device functionality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Certain configuration endpoints may lack proper server-side 
authorization checks, allowing unauthorized users to access or modify 
sensitive device settings. This could result in full compromise of 
device functionality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7mpm-96ch-vg98</guid>
    </item>
    <item>
      <title>ICSA-26-237-06 — Ebyte NE2-D11</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-237-06</link>
      <description>&lt;p&gt;Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality. Administrative credentials may be exposed in plaintext within the Ebyte device&amp;#39;s management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access. Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful exploitation could result in disclosure of sensitive information and unauthorized access to device management functionality. Administrative credentials may be exposed in plaintext within the Ebyte device&amp;#39;s management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device access. Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device. An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-237-06</guid>
    </item>
  </channel>
</rss>
