<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:06:23 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-16848</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-16848</link>
      <description>cnvd-2020-16848</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-16848</guid>
    </item>
    <item>
      <title>EUVD-2026-50014</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-50014</link>
      <description>EUVD-2026-50014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-50014</guid>
    </item>
    <item>
      <title>fkie_cve-2019-5170</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-5170</link>
      <description>&lt;p&gt;An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=&amp;lt;contents of hostname node&amp;gt; using sprintf(). This command is later executed via a call to system().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=&amp;lt;contents of hostname node&amp;gt; using sprintf(). This command is later executed via a call to system().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-5170</guid>
    </item>
    <item>
      <title>GHSA-59q2-93ch-m6p9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-59q2-93ch-m6p9</link>
      <description>&lt;p&gt;An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=&amp;lt;contents of hostname node&amp;gt; using sprintf(). This command is later executed via a call to system().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=&amp;lt;contents of hostname node&amp;gt; using sprintf(). This command is later executed via a call to system().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-59q2-93ch-m6p9</guid>
    </item>
    <item>
      <title>gsd-2019-5170</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-5170</link>
      <description>gsd-2019-5170</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-5170</guid>
    </item>
    <item>
      <title>VDE-2020-011 — WAGO: Multiple Vulnerabilities in I/O-Check Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-011</link>
      <description>&lt;p&gt;An attacker needs an authorized login on the device in order to exploit the herein mentioned vulnerabilities.&lt;/p&gt;
&lt;p&gt;The reported vulnerabilities allow a local attacker with valid login credentials who is able to create files on the device to change the devices settings, e.g. default gateway address, time server etc. and potentially execute code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker needs an authorized login on the device in order to exploit the herein mentioned vulnerabilities.&lt;/p&gt;
&lt;p&gt;The reported vulnerabilities allow a local attacker with valid login credentials who is able to create files on the device to change the devices settings, e.g. default gateway address, time server etc. and potentially execute code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-011</guid>
    </item>
  </channel>
</rss>
