5.4
CVSSv3

CVE-2021-31250

Published: 04/06/2021 Updated: 08/06/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chiyu-tech bf-430_firmware -

chiyu-tech bf-431_firmware -

chiyu-tech bf-450m_firmware -

Vendor Advisories

Check Point Reference: CPAI-2021-2117 Date Published: 12 Mar 2024 Severity: Medium ...

Exploits

CHIYU IoT devices suffer from multiple cross site scripting vulnerabilities Versions affected include BF-430, BF-431, BF-450M, BF-630, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC ...