<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_welotecgmbh</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:09:31 +0000</lastBuildDate>
    <item>
      <title>VDE-2025-085 — Welotec: Path Traversal in SmartEMS Upload Handling</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-085</link>
      <description>&lt;p&gt;A path traversal flaw in the SmartEMS upload handling allows authenticated users to direct upload data outside of the intended directory via the &amp;#39;Upload-Key&amp;#39; header. In deployments where writable, code-interpreted paths are reachable, this may lead to remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A path traversal flaw in the SmartEMS upload handling allows authenticated users to direct upload data outside of the intended directory via the &amp;#39;Upload-Key&amp;#39; header. In deployments where writable, code-interpreted paths are reachable, this may lead to remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-085</guid>
      <pubDate>Wed, 10 Sep 2025 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-076 — Welotec: Hard-coded JWT secret in egOS WebGUI</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-076</link>
      <description>&lt;p&gt;A hard-coded JWT secret in the egOS WebGUI backend is readable to the default user, allowing attackers to forge valid tokens and access protected API endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A hard-coded JWT secret in the egOS WebGUI backend is readable to the default user, allowing attackers to forge valid tokens and access protected API endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-076</guid>
      <pubDate>Tue, 26 Aug 2025 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-009 — Welotec: Two vulnerabilities in TK500v1 router series</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-009</link>
      <description>&lt;p&gt;An unauthenticated remote attacker who is aware of a MQTT  topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
 An remote attacker with low privileges can perform a command injection which can lead to root access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker who is aware of a MQTT  topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
 An remote attacker with low privileges can perform a command injection which can lead to root access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-009</guid>
      <pubDate>Tue, 09 Apr 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-043 — Welotec: Multiple products are vulnerable to regreSSHion</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-043</link>
      <description>&lt;p&gt;Products from the Edge Gateway Family are affected by recently published so called RegreSSHion vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Products from the Edge Gateway Family are affected by recently published so called RegreSSHion vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-043</guid>
      <pubDate>Thu, 22 Aug 2024 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-023 — Welotec: Clickjacking Vulnerability in WebUI</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-023</link>
      <description>&lt;p&gt;Welotec has been informed by an external source that the WebUI of the device management solution &amp;#34;SMART EMS&amp;#34; and the remote connectivity solution &amp;#34;VPN Security Suite&amp;#34; is vulnerable to so-called &amp;#34;Clickjacking&amp;#34; and advises to update to version v3.1.4 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Welotec has been informed by an external source that the WebUI of the device management solution &amp;#34;SMART EMS&amp;#34; and the remote connectivity solution &amp;#34;VPN Security Suite&amp;#34; is vulnerable to so-called &amp;#34;Clickjacking&amp;#34; and advises to update to version v3.1.4 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-023</guid>
      <pubDate>Tue, 23 Apr 2024 08:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
