<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 08:19:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-187015</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187015</link>
      <description>EUVD-2026-187015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187015</guid>
    </item>
    <item>
      <title>fkie_cve-2023-39429</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39429</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-39429</guid>
    </item>
    <item>
      <title>GHSA-4r8h-f85r-q588</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4r8h-f85r-q588</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware ver.01.35 and earlier, ACERA 1110 firmware ver.01.76 and earlier, ACERA 1020 firmware ver.01.86 and earlier, ACERA 1010 firmware ver.01.86 and earlier, ACERA 950 firmware ver.01.60 and earlier, ACERA 850F firmware ver.01.60 and earlier, ACERA 900 firmware ver.02.54 and earlier, ACERA 850M firmware ver.02.06 and earlier, ACERA 810 firmware ver.03.74 and earlier, and ACERA 800ST firmware ver.07.35 and earlier. They are affected when running in ST(Standalone) mode.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4r8h-f85r-q588</guid>
    </item>
    <item>
      <title>gsd-2023-39429</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-39429</link>
      <description>gsd-2023-39429</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-39429</guid>
    </item>
    <item>
      <title>jvndb-2023-003767</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2023-003767</link>
      <description>&lt;p&gt;Wireless LAN access point devices provided by FURUNO SYSTEMS Co.,Ltd., running in ST(Standalone) mode, contain multiple vulnerabilities listed below.&#13;
&#13;
* OS Command Injection (CWE-78) - CVE-2023-39222&#13;
* Cross-site Scripting (CWE-79) - CVE-2023-39429&#13;
* Cross-Site Request Forgery (CWE-352) - CVE-2023-41086&#13;
* Authentication Bypass (CWE-288) - CVE-2023-42771&#13;
* Path traversal (CWE-22) - CVE-2023-43627&#13;
&#13;
Katsuhiko Sato(a.k.a. goroh_kun) of 00One, Inc. reported OS Command Injection vulnerability (CVE-2023-39222) to JPCERT/CC.&#13;
JPCERT/CC coordinated with the developer.&#13;
&#13;
As a result of the developer&amp;#39;s investigation into this report, other vulnerabilities were newly discovered and addressed.&#13;
The developer reported these vulnerabilities to notify users of the solution through JVN. JPCERT/CC coordinated with the developer for the publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wireless LAN access point devices provided by FURUNO SYSTEMS Co.,Ltd., running in ST(Standalone) mode, contain multiple vulnerabilities listed below.&#13;
&#13;
* OS Command Injection (CWE-78) - CVE-2023-39222&#13;
* Cross-site Scripting (CWE-79) - CVE-2023-39429&#13;
* Cross-Site Request Forgery (CWE-352) - CVE-2023-41086&#13;
* Authentication Bypass (CWE-288) - CVE-2023-42771&#13;
* Path traversal (CWE-22) - CVE-2023-43627&#13;
&#13;
Katsuhiko Sato(a.k.a. goroh_kun) of 00One, Inc. reported OS Command Injection vulnerability (CVE-2023-39222) to JPCERT/CC.&#13;
JPCERT/CC coordinated with the developer.&#13;
&#13;
As a result of the developer&amp;#39;s investigation into this report, other vulnerabilities were newly discovered and addressed.&#13;
The developer reported these vulnerabilities to notify users of the solution through JVN. JPCERT/CC coordinated with the developer for the publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2023-003767</guid>
    </item>
  </channel>
</rss>
