<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:34:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274751</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274751</link>
      <description>EUVD-2026-274751</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274751</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23767</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23767</link>
      <description>&lt;p&gt;ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23767</guid>
    </item>
    <item>
      <title>GHSA-57q8-p4r4-7xr7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-57q8-p4r4-7xr7</link>
      <description>&lt;p&gt;ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-57q8-p4r4-7xr7</guid>
    </item>
    <item>
      <title>jvndb-2026-006102</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-006102</link>
      <description>&lt;p&gt;ESC/POS is a printer control language designed by Seiko Epson Corporation for controlling POS printers and related devices. The following security issues have been identified with ESC/POS.&#13;
Products implementing ESC/POS need to be designed and operated with consideration of the following security issues:&#13;
&#13;
Missing authentication for critical function (CWE-306)&#13;
ESC/POS does not define any mechanisms for user authentication or command authorization. Consequently, printers accepting ESC/POS commands over a network have no restrictions on connections, allowing commands to be sent from any host on the network.&#13;
&#13;
Improper access control (CWE-284)&#13;
ESC/POS does not define any mechanisms to restrict origins or destinations of communication. Many printers listen for ESC/POS communication on TCP port 9100 by default, potentially allowing access from any host on the network.&#13;
&#13;
Cleartext transmission of sensitive information (CWE-319)&#13;
ESC/POS command transmission does not provide encryption or integrity protection mechanisms, and communicate is performed in plaintext. Consequently, attackers on the same network could be able to intercept or tamper with transmitted data.&#13;
&#13;
JPCERT/CC has assigned CVE-2026-23767 to the vulnerability originating from the ESC/POS specification.&#13;
This document was written by Seiko Epson Corporation and JPCERT/CC.&#13;
The issue regarding the lack of an authentication mechanism was reported to Seiko Epson Corporation by Michael Cook (FutileSkills), and coord…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ESC/POS is a printer control language designed by Seiko Epson Corporation for controlling POS printers and related devices. The following security issues have been identified with ESC/POS.&#13;
Products implementing ESC/POS need to be designed and operated with consideration of the following security issues:&#13;
&#13;
Missing authentication for critical function (CWE-306)&#13;
ESC/POS does not define any mechanisms for user authentication or command authorization. Consequently, printers accepting ESC/POS commands over a network have no restrictions on connections, allowing commands to be sent from any host on the network.&#13;
&#13;
Improper access control (CWE-284)&#13;
ESC/POS does not define any mechanisms to restrict origins or destinations of communication. Many printers listen for ESC/POS communication on TCP port 9100 by default, potentially allowing access from any host on the network.&#13;
&#13;
Cleartext transmission of sensitive information (CWE-319)&#13;
ESC/POS command transmission does not provide encryption or integrity protection mechanisms, and communicate is performed in plaintext. Consequently, attackers on the same network could be able to intercept or tamper with transmitted data.&#13;
&#13;
JPCERT/CC has assigned CVE-2026-23767 to the vulnerability originating from the ESC/POS specification.&#13;
This document was written by Seiko Epson Corporation and JPCERT/CC.&#13;
The issue regarding the lack of an authentication mechanism was reported to Seiko Epson Corporation by Michael Cook (FutileSkills), and coord…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-006102</guid>
    </item>
  </channel>
</rss>
