An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Chiyu-tech
Subscribe
|
Bf-430
Subscribe
Bf-430 Firmware
Subscribe
Bf-431
Subscribe
Bf-431 Firmware
Subscribe
Bf-450m
Subscribe
Bf-450m Firmware
Subscribe
Bf-630
Subscribe
Bf-630 Firmware
Subscribe
Bf-631w
Subscribe
Bf-631w Firmware
Subscribe
Bf-830w
Subscribe
Bf-830w Firmware
Subscribe
Bfminiw
Subscribe
Bfminiw Firmware
Subscribe
Semac D1
Subscribe
Semac D1 Firmware
Subscribe
Semac D2
Subscribe
Semac D2 Firmware
Subscribe
Semac D2 N300
Subscribe
Semac D2 N300 Firmware
Subscribe
Semac D4
Subscribe
Semac D4 Firmware
Subscribe
Semac S1 Osdp
Subscribe
Semac S1 Osdp Firmware
Subscribe
Semac S2
Subscribe
Semac S2 Firmware
Subscribe
Semac S3v3
Subscribe
Semac S3v3 Firmware
Subscribe
Webpass
Subscribe
Webpass Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18529 | An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:03:33.666Z
Reserved: 2021-04-23T00:00:00.000Z
Link: CVE-2021-31641
No data.
Status : Modified
Published: 2021-06-01T15:15:07.680
Modified: 2024-11-21T06:06:03.687
Link: CVE-2021-31641
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD