<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:02:58 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-37023 — Vonets WiFi Bridges Command Injection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-37023</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Vonets VAR1200-H, Vonets VAR1200-L, Vonets VAR600-H, Vonets VAP11AC, Vonets VAP11G-500S, Vonets VBG1200, Vonets VAP11S-5G, Vonets VAP11S, Vonets VAR11N-300, Vonets VAP11G-300 and 17 more&lt;/p&gt;
&lt;p&gt;Multiple OS command injection vulnerabilities affecting Vonets&lt;/p&gt;
&lt;p&gt;industrial wifi bridge relays and wifi bridge repeaters, software 
versions 3.3.23.6.9 and prior, enable an authenticated remote attacker 
to execute arbitrary OS commands via various endpoint parameters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Vonets VAR1200-H, Vonets VAR1200-L, Vonets VAR600-H, Vonets VAP11AC, Vonets VAP11G-500S, Vonets VBG1200, Vonets VAP11S-5G, Vonets VAP11S, Vonets VAR11N-300, Vonets VAP11G-300 and 17 more&lt;/p&gt;
&lt;p&gt;Multiple OS command injection vulnerabilities affecting Vonets&lt;/p&gt;
&lt;p&gt;industrial wifi bridge relays and wifi bridge repeaters, software 
versions 3.3.23.6.9 and prior, enable an authenticated remote attacker 
to execute arbitrary OS commands via various endpoint parameters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-37023</guid>
    </item>
    <item>
      <title>ICSA-24-214-08 — Vonets WiFi Bridges</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-214-08</link>
      <description>&lt;p&gt;Use of Hard-coded Credentials vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication using hard-coded administrator credentials. These accounts cannot be disabled.  Improper Access Control vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints.  A Directory Traversal vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to read arbitrary files and bypass authentication.  Multiple OS Command Injection vulnerabilities affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker to execute arbitrary OS commands via various endpoint parameters.  Improper Check or Handling of Exceptional Conditions vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a Denial-of-Service (DoS). A specially-crafted HTTP request to preauthentication resources can crash the service.  Stack-Based Buffer Overflow vulnerabilities affectin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of Hard-coded Credentials vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication using hard-coded administrator credentials. These accounts cannot be disabled.  Improper Access Control vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints.  A Directory Traversal vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to read arbitrary files and bypass authentication.  Multiple OS Command Injection vulnerabilities affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker to execute arbitrary OS commands via various endpoint parameters.  Improper Check or Handling of Exceptional Conditions vulnerability affecting Vonets Industrial WiFi Bridge Relays and WiFi Bridge Repeaters software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a Denial-of-Service (DoS). A specially-crafted HTTP request to preauthentication resources can crash the service.  Stack-Based Buffer Overflow vulnerabilities affectin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-214-08</guid>
    </item>
  </channel>
</rss>
