<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CFSE Consequence Paths Registry</title><link>https://paths.cfse.ai/</link><description>Cyber-physical consequence scoring for authority, perception, physical/safety, systemic reach, and recovery burden.</description><item><title>CPATH-2026-0034 · August Smart Lock Pro + Connect Wi-Fi password disclosure via hardcoded key (CVE-2019-17098)</title><link>https://paths.cfse.ai/CPATH-2026-0034</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0034</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band HIGH; dominant consequence Data privacy. This path is explicitly dominant because it reaches the record's highest candidate band, HIGH. Published baseline 6.5 MEDIUM.</description></item><item><title>CPATH-2026-0040 · B. Braun Infusomat/Perfusor Space (SpaceCom2 / Battery pack SP with Wi-Fi) - remote unauthenticated dose alteration</title><link>https://paths.cfse.ai/CPATH-2026-0040</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0040</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 10 CRITICAL.</description></item><item><title>CPATH-2026-0005 · Baxter Life2000 hard-coded clinician credentials</title><link>https://paths.cfse.ai/CPATH-2026-0005</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0005</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Account authority. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 9.3 CRITICAL.</description></item><item><title>CPATH-2026-0002 · Baxter Life2000 — insufficient audit logging</title><link>https://paths.cfse.ai/CPATH-2026-0002</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0002</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band MONITOR; dominant consequence Observability and recovery. Observability and recovery is the only modeled consequence because insufficient logging creates no independent exploit primitive or reachable authority; MONITOR is therefore explicit, not an array-order default. Published baseline 10 CRITICAL.</description></item><item><title>CPATH-2026-0004 · Baxter Life2000 internal JTAG flash R/W</title><link>https://paths.cfse.ai/CPATH-2026-0004</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0004</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Firmware trust root. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 9.3 CRITICAL.</description></item><item><title>CPATH-2026-0039 · Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI</title><link>https://paths.cfse.ai/CPATH-2026-0039</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0039</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band HIGH; co-dominant consequences Account authority and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied. Published baseline 4.2 MEDIUM.</description></item><item><title>CPATH-2026-0033 · Chirp Systems / Chirp Access smart-lock app hardcoded credentials (CVE-2024-2197)</title><link>https://paths.cfse.ai/CPATH-2026-0033</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0033</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band HIGH; co-dominant consequences Account authority and Device-control safety. These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied. Published baseline 4.3 MEDIUM.</description></item><item><title>CPATH-2026-0003 · Contec CMS8000 — unsigned-firmware load / hard-coded beacon</title><link>https://paths.cfse.ai/CPATH-2026-0003</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0003</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Firmware trust root and Device-control safety and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 8.2 HIGH.</description></item><item><title>CPATH-2026-0006 · Contec CMS8000 out-of-bounds write via UDP</title><link>https://paths.cfse.ai/CPATH-2026-0006</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0006</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Device-control safety and Device availability and recovery. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0030 · Dahua IP camera / VTH / VTO authentication bypass (CVE-2021-33044)</title><link>https://paths.cfse.ai/CPATH-2026-0030</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0030</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Device-control safety and Account authority. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0020 · DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)</title><link>https://paths.cfse.ai/CPATH-2026-0020</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0020</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Perception privacy. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 6.6 MEDIUM.</description></item><item><title>CPATH-2026-0016 · Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)</title><link>https://paths.cfse.ai/CPATH-2026-0016</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0016</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Perception privacy. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. No published baseline.</description></item><item><title>CPATH-2026-0013 · GAZEploit: keystroke inference from Vision Pro Persona eye movements (CVE-2024-40865)</title><link>https://paths.cfse.ai/CPATH-2026-0013</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0013</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Perception privacy and Account authority. The privacy and account paths are co-dominant at CRITICAL because one outward Persona channel can disclose typed content and, conditionally, credentials that cross into account authority; neither is selected by array order. Published baseline 5.3 MEDIUM.</description></item><item><title>CPATH-2026-0038 · GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key</title><link>https://paths.cfse.ai/CPATH-2026-0038</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0038</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Perception-to-action and Device-control safety. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 10 CRITICAL.</description></item><item><title>CPATH-2026-0022 · GPS/GNSS Spoofing Safe-Hijacking of Consumer Drones (Adaptive GPS Spoofing / Tractor Beam class)</title><link>https://paths.cfse.ai/CPATH-2026-0022</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0022</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Perception-to-action and Device-control safety. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. No published baseline.</description></item><item><title>CPATH-2026-0029 · Hikvision IP camera / NVR unauthenticated command injection (CVE-2021-36260)</title><link>https://paths.cfse.ai/CPATH-2026-0029</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0029</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Perception-to-action and Account authority and Fleet control plane. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0014 · HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503)</title><link>https://paths.cfse.ai/CPATH-2026-0014</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0014</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Device-control safety. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 8.8 HIGH.</description></item><item><title>CPATH-2026-0015 · HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972)</title><link>https://paths.cfse.ai/CPATH-2026-0015</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0015</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Device availability and recovery. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 6.5 MEDIUM.</description></item><item><title>CPATH-2026-0012 · Inception Attack: malicious VR app hijacks the entire Meta Quest environment (UChicago, 2024)</title><link>https://paths.cfse.ai/CPATH-2026-0012</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0012</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Perception-to-action and Perception privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. No published baseline.</description></item><item><title>CPATH-2026-0035 · Medtronic Conexus RF telemetry protocol lacks authentication/encryption (implantable cardiac devices)</title><link>https://paths.cfse.ai/CPATH-2026-0035</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0035</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 9.3 CRITICAL.</description></item><item><title>CPATH-2026-0036 · Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control</title><link>https://paths.cfse.ai/CPATH-2026-0036</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0036</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 8.8 HIGH.</description></item><item><title>CPATH-2026-0037 · Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation</title><link>https://paths.cfse.ai/CPATH-2026-0037</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0037</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Device-control safety. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 4.8 MEDIUM.</description></item><item><title>CPATH-2026-0032 · Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297)</title><link>https://paths.cfse.ai/CPATH-2026-0032</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0032</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band HIGH; co-dominant consequences Account authority and Device availability and recovery and Data privacy. These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied. Published baseline 9.2 CRITICAL.</description></item><item><title>CPATH-2026-0021 · Phantom of the ADAS: Projected/Billboard Phantom Object Attacks on Tesla Autopilot and Mobileye</title><link>https://paths.cfse.ai/CPATH-2026-0021</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0021</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Perception-to-action. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. No published baseline.</description></item><item><title>CPATH-2026-0017 · PX4 Autopilot MAVLink Unauthenticated Remote Shell (CVE-2026-1579)</title><link>https://paths.cfse.ai/CPATH-2026-0017</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0017</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; dominant consequence Device-control safety. This path is explicitly dominant because it reaches the record's highest candidate band, EMERGENCY. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0001 · Qardio Arm — static credentials → engineering backdoor</title><link>https://paths.cfse.ai/CPATH-2026-0001</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0001</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Account authority. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 6.6 MEDIUM.</description></item><item><title>CPATH-2026-0007 · Qardio BLE unauthenticated DoS (startMeasurement flood)</title><link>https://paths.cfse.ai/CPATH-2026-0007</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0007</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band ELEVATED; dominant consequence Device availability and recovery. This path is explicitly dominant because it reaches the record's highest candidate band, ELEVATED. Published baseline 7.1 HIGH.</description></item><item><title>CPATH-2026-0008 · Qardio firmware files extractable</title><link>https://paths.cfse.ai/CPATH-2026-0008</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0008</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band HIGH; dominant consequence Data privacy. This path is explicitly dominant because it reaches the record's highest candidate band, HIGH. Published baseline 6.9 MEDIUM.</description></item><item><title>CPATH-2026-0011 · SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)</title><link>https://paths.cfse.ai/CPATH-2026-0011</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0011</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Perception-to-action and Account authority. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 8.8 HIGH.</description></item><item><title>CPATH-2026-0009 · Swisslog Translogic PTS unsigned firmware update</title><link>https://paths.cfse.ai/CPATH-2026-0009</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0009</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Firmware trust root and Fleet control plane. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0010 · Swisslog Translogic TLP20 tcpTxThread stack overflow</title><link>https://paths.cfse.ai/CPATH-2026-0010</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0010</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Device availability and recovery. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item><item><title>CPATH-2026-0028 · Teleoperated surgical robot (Raven II) command hijacking &amp; E-stop abuse</title><link>https://paths.cfse.ai/CPATH-2026-0028</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0028</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Perception-to-action and Device-control safety and Device availability and recovery. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. No published baseline.</description></item><item><title>CPATH-2026-0019 · Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156)</title><link>https://paths.cfse.ai/CPATH-2026-0019</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0019</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Firmware trust root. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 9 CRITICAL.</description></item><item><title>CPATH-2026-0018 · Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082)</title><link>https://paths.cfse.ai/CPATH-2026-0018</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0018</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Perception-to-action. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 7.5 HIGH.</description></item><item><title>CPATH-2026-0031 · TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389)</title><link>https://paths.cfse.ai/CPATH-2026-0031</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0031</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Account authority and Fleet control plane. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 8.8 HIGH.</description></item><item><title>CPATH-2026-0026 · Unitree Go1 CloudSail undocumented remote-access backdoor (CVE-2025-2894)</title><link>https://paths.cfse.ai/CPATH-2026-0026</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0026</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Device-control safety and Fleet control plane. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 6.6 MEDIUM.</description></item><item><title>CPATH-2026-0025 · Unitree Go2 Android-app database tampering RCE (CVE-2026-27510)</title><link>https://paths.cfse.ai/CPATH-2026-0025</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0025</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; dominant consequence Perception privacy. This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL. Published baseline 9.6 CRITICAL.</description></item><item><title>CPATH-2026-0024 · Unitree Go2 unauthenticated DDS RCE via programming_actuator topic (CVE-2026-27509)</title><link>https://paths.cfse.ai/CPATH-2026-0024</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0024</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band CRITICAL; co-dominant consequences Device-control safety and Perception privacy. These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied. Published baseline 8.5 HIGH.</description></item><item><title>CPATH-2026-0023 · Unitree UniPwn — BLE Wi-Fi config root takeover (Go2/B2/G1/H1)</title><link>https://paths.cfse.ai/CPATH-2026-0023</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0023</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; dominant consequence Fleet control plane. The fleet-control-plane path is dominant because documented peer scanning can reuse the shared key across in-range robots, producing the only fleet-scale EMERGENCY path; motion and privacy remain supporting CRITICAL paths. Published baseline 8.2 HIGH.</description></item><item><title>CPATH-2026-0027 · Universal Robots PolyScope 5 Dashboard Server OS command injection (CVE-2026-8153)</title><link>https://paths.cfse.ai/CPATH-2026-0027</link><guid isPermaLink="true">https://paths.cfse.ai/CPATH-2026-0027</guid><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><description>Candidate Paths band EMERGENCY; co-dominant consequences Device-control safety and Fleet control plane and Account authority. These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied. Published baseline 9.8 CRITICAL.</description></item></channel></rss>