Back to Database
Status published
Medium
CVE-2021-31643
An XSS vulnerability exists in several IoT devices from CHIYU...
Vulnerability Description
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31643
Credits & Attribution
No credits recorded in the NVD database.
References
- https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks/
- https://www.chiyu-tech.com/msg/message-Firmware-update-87.html
- https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices#cve-2021-31643
- http://packetstormsecurity.com/files/162887/CHIYU-IoT-Cross-Site-Scripting.html
More from chiyu-tech
View All →CVE-2021-31642
A denial of service condition exists after an integer overflow...
Medium
6.5
CVE-2021-31641
An unauthenticated XSS vulnerability exists in several IoT devices from...
Medium
6.1
CVE-2021-31252
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431,...
Medium
6.1
CVE-2021-31251
An authentication bypass in telnet server in BF-430 and BF431...
Critical
9.8
CVE-2021-31250
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and...
Medium
5.4
Affected Vendor
chiyu-tech
View all reports →Affected Software
bf-631 firmware, bf-630 firmware, semac s2 firmware, semac d1 firmware, semac d2 firmware, semac d4 firmware, semac s3v3 firmware, semac d2 n300 firmware, semac s1 osdp firmware, webpass firmware, biosense firmware
Vulnerable Versions:
Unknown
Timeline
Official Publish:
June 1st, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.