<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266639</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266639</link>
      <description>EUVD-2026-266639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266639</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41727</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41727</link>
      <description>&lt;p&gt;A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41727</guid>
    </item>
    <item>
      <title>GHSA-f6mf-xjgg-34j8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f6mf-xjgg-34j8</link>
      <description>&lt;p&gt;A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f6mf-xjgg-34j8</guid>
    </item>
    <item>
      <title>VDE-2025-092 — Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-092</link>
      <description>&lt;p&gt;The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.&lt;/p&gt;
&lt;p&gt;The vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-092</guid>
    </item>
  </channel>
</rss>
