CVE-2025-2863 - CVE House
Back to Database
Status published Medium CVE-2025-2863

Cross-site request forgery (CSRF) vulnerability in saTECH BCU

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in the web application of saTECH BCU firmware version 2.1.3, which could allow an unauthenticated local attacker to exploit active administrator sessions and perform malicious actions. The malicious actions that can be executed by the attacker depend on the logged-in user, and may include rebooting the device or modifying roles and permissions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2863

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Aarón Flecha
  • Gabriel Vía Echezarreta

Affected Vendor

Affected Software

saTECH BCU
Vulnerable Versions:
2.1.3

Timeline

Official Publish: March 28th, 2025
Last Modified: March 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)