CVE-2021-31643
moderate-risk
Published 2021-06-01
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
Do I need to act?
~
3.8% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.4/10
Medium
NETWORK
/ LOW complexity
Affected Products (11)
Bf-630 Firmware
Semac S2 Firmware
Semac D1 Firmware
Semac D2 Firmware
Semac D4 Firmware
Semac S3V3 Firmware
Semac D2 N300 Firmware
Semac S1 Osdp Firmware
Webpass Firmware
Affected Vendors
References (8)
Vendor Advisory
https://www.chiyu-tech.com/msg/message-Firmware-update-87.html
Vendor Advisory
https://www.chiyu-tech.com/msg/message-Firmware-update-87.html
44
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
7/34 · Low
Exposure
16/34 · Moderate