ZeroHour

CVE-2021-31643

PoC ×3
CVSS 3.1
5.4 medium
EPSS
88%p100
Published
()
Modified
Description

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

Vendors
chiyu-tech
Products
bf-631 firmware, bf-630 firmware, semac s2 firmware, semac d1 firmware, semac d2 firmware, semac d4 firmware, semac s3v3 firmware, semac d2 n300 firmware, semac s1 osdp firmware, webpass firmware, biosense firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.