ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-46480
Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sn

Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.

NVD description · AI analysis pending
8.1<1% PoC
  • u-tec ultraloq ul3 bt firmware
CVE-2021-31251
+3 in the same advisory: …31249 …31252 …31250
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privilege

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

NVD description · AI analysis pending
9.8
group max
36% PoC ×2
  • chiyu-tech bf-430 firmware
  • chiyu-tech bf-431 firmware
  • chiyu-tech bf-450m firmware
  • +1 more
CVE-2021-31643
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization o

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

NVD description · AI analysis pending
5.488% PoC ×3
  • chiyu-tech bf-631 firmware
  • chiyu-tech bf-630 firmware
  • chiyu-tech semac s2 firmware
  • +1 more
CVE-2021-31642
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, an

A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.

NVD description · AI analysis pending
6.544% PoC ×3
  • chiyu-tech semac s2 firmware
  • chiyu-tech semac d1 firmware
  • chiyu-tech semac d2 firmware
  • +1 more
CVE-2021-31641
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass,

An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

NVD description · AI analysis pending
6.15% PoC ×3
  • chiyu-tech bf-430 firmware
  • chiyu-tech bf-431 firmware
  • chiyu-tech bf-450m firmware
  • +1 more