<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 12:04:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278143</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278143</link>
      <description>EUVD-2026-278143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278143</guid>
    </item>
    <item>
      <title>fkie_cve-2024-51977</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-51977</link>
      <description>&lt;p&gt;An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-51977</guid>
    </item>
    <item>
      <title>GHSA-27h4-8c24-mx7w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-27h4-8c24-mx7w</link>
      <description>&lt;p&gt;An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-27h4-8c24-mx7w</guid>
    </item>
    <item>
      <title>jvndb-2025-007519</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-007519</link>
      <description>&lt;p&gt;Multiple BROTHER products provided by BROTHER INDUSTRIES, LTD. contain multiple vulnerabilities listed below.&#13;
&#13;
* Exposure of sensitive system information to an unauthorized control sphere (CWE-497) - CVE-2024-51977&#13;
* Use of weak credentials (CWE-1391) - CVE-2024-51978&#13;
* Stack-based buffer overflow (CWE-121) - CVE-2024-51979&#13;
* Server-side request forgery (CWE-918) - CVE-2024-51980, CVE-2024-51981&#13;
* Improper handling of unexpected data type (CWE-241) - CVE-2024-51982&#13;
* Improper enforcement of behavioral workflow (CWE-841) - CVE-2024-51983&#13;
* Insufficiently protected credentials (CWE-522) - CVE-2024-51984&#13;
&#13;
Stephen Fewer of Rapid7 reported this vulnerability to the developer.&#13;
JPCERT/CC coordinated between the reporter and the developer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple BROTHER products provided by BROTHER INDUSTRIES, LTD. contain multiple vulnerabilities listed below.&#13;
&#13;
* Exposure of sensitive system information to an unauthorized control sphere (CWE-497) - CVE-2024-51977&#13;
* Use of weak credentials (CWE-1391) - CVE-2024-51978&#13;
* Stack-based buffer overflow (CWE-121) - CVE-2024-51979&#13;
* Server-side request forgery (CWE-918) - CVE-2024-51980, CVE-2024-51981&#13;
* Improper handling of unexpected data type (CWE-241) - CVE-2024-51982&#13;
* Improper enforcement of behavioral workflow (CWE-841) - CVE-2024-51983&#13;
* Insufficiently protected credentials (CWE-522) - CVE-2024-51984&#13;
&#13;
Stephen Fewer of Rapid7 reported this vulnerability to the developer.&#13;
JPCERT/CC coordinated between the reporter and the developer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-007519</guid>
    </item>
  </channel>
</rss>
