CVE-2021-31641

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/06/2021
Last modified:
08/06/2021

Description

An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:chiyu-tech:bf-430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:bf-430:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:bf-431_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:bf-431:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:bf-450m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:bf-450m:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:semac_s2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:semac_s2:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:semac_d1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:semac_d1:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:semac_d2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:semac_d2:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:semac_d4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:chiyu-tech:semac_d4:-:*:*:*:*:*:*:*
cpe:2.3:o:chiyu-tech:semac_s3v3_firmware:-:*:*:*:*:*:*:*