<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:20:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322799</link>
      <description>EUVD-2026-322799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322799</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9037</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9037</link>
      <description>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9037</guid>
    </item>
    <item>
      <title>GHSA-6qw7-34qq-r69v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6qw7-34qq-r69v</link>
      <description>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6qw7-34qq-r69v</guid>
    </item>
    <item>
      <title>ICSA-26-148-08 — XCharge C6</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-148-08</link>
      <description>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device, A stack-based buffer overflow vulnerability in the charging controller&amp;#39;s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges. A configuration weakness in the device&amp;#39;s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device&amp;#39;s management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device, A stack-based buffer overflow vulnerability in the charging controller&amp;#39;s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges. A configuration weakness in the device&amp;#39;s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-148-08</guid>
    </item>
  </channel>
</rss>
