CVE-2021-31641

moderate-risk
Published 2021-06-01

An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

Do I need to act?

~
1.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10 Medium
NETWORK / LOW complexity

Affected Products (15)

Semac S2 Firmware
Semac D1 Firmware
Semac D2 Firmware
Semac D4 Firmware
Semac S3V3 Firmware
Semac D2 N300 Firmware
Semac S1 Osdp Firmware
Bf-630 Firmware
Bf-631W Firmware
Bf-830W Firmware
Webpass Firmware
Bfminiw Firmware

Affected Vendors

44
/ 100
moderate-risk
Severity 23/34 · High
Exploitability 3/34 · Minimal
Exposure 18/34 · Moderate