<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:43:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-361118</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361118</link>
      <description>EUVD-2026-361118</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361118</guid>
    </item>
    <item>
      <title>fkie_cve-2026-76943</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76943</link>
      <description>&lt;p&gt;Xiiaozet LK100Wt contains an authentication weakness within an 
administrative service that may allow an attacker to bypass intended 
access controls and obtain command execution capabilities. Successful 
exploitation could allow unauthorized interaction with privileged 
functionality and may lead to complete device compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Xiiaozet LK100Wt contains an authentication weakness within an 
administrative service that may allow an attacker to bypass intended 
access controls and obtain command execution capabilities. Successful 
exploitation could allow unauthorized interaction with privileged 
functionality and may lead to complete device compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-76943</guid>
    </item>
    <item>
      <title>GHSA-6x82-vfrh-gxpc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x82-vfrh-gxpc</link>
      <description>&lt;p&gt;Xiiaozet LK100Wt contains an authentication weakness within an 
administrative service that may allow an attacker to bypass intended 
access controls and obtain command execution capabilities. Successful 
exploitation could allow unauthorized interaction with privileged 
functionality and may lead to complete device compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Xiiaozet LK100Wt contains an authentication weakness within an 
administrative service that may allow an attacker to bypass intended 
access controls and obtain command execution capabilities. Successful 
exploitation could allow unauthorized interaction with privileged 
functionality and may lead to complete device compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x82-vfrh-gxpc</guid>
    </item>
    <item>
      <title>ICSA-26-239-01 — Xiiaozet LK100W</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-239-01</link>
      <description>&lt;p&gt;Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device. Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device. Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-239-01</guid>
    </item>
  </channel>
</rss>
