CVE-2021-31641
moderate-risk
Published 2021-06-01
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.
Do I need to act?
~
1.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10
Medium
NETWORK
/ LOW complexity
Affected Products (15)
Semac S2 Firmware
Semac D1 Firmware
Semac D2 Firmware
Semac D4 Firmware
Semac S3V3 Firmware
Semac D2 N300 Firmware
Semac S1 Osdp Firmware
Bf-630 Firmware
Bf-631W Firmware
Bf-830W Firmware
Webpass Firmware
Bfminiw Firmware
Affected Vendors
References (8)
Vendor Advisory
https://www.chiyu-tech.com/msg/message-Firmware-update-87.html
Vendor Advisory
https://www.chiyu-tech.com/msg/message-Firmware-update-87.html
44
/ 100
moderate-risk
Severity
23/34 · High
Exploitability
3/34 · Minimal
Exposure
18/34 · Moderate