// For flags

CVE-2021-31641

CHIYU IoT Cross Site Scripting

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

Se presenta una vulnerabilidad de tipo XSS no autenticada en varios dispositivos IoT de CHIYU Technology, incluyendo BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, y SEMAC debido a una falta de sanitizaciĆ³n cuando es generado el mensaje HTTP 404

CHIYU IoT devices suffer from multiple cross site scripting vulnerabilities. Versions affected include BF-430, BF-431, BF-450M, BF-630, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-23 CVE Reserved
  • 2021-06-01 CVE Published
  • 2021-06-01 First Exploit
  • 2024-08-03 CVE Updated
  • 2025-02-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-430 Firmware
Search vendor "Chiyu-tech" for product "Bf-430 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-430
Search vendor "Chiyu-tech" for product "Bf-430"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-431 Firmware
Search vendor "Chiyu-tech" for product "Bf-431 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-431
Search vendor "Chiyu-tech" for product "Bf-431"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-450m Firmware
Search vendor "Chiyu-tech" for product "Bf-450m Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-450m
Search vendor "Chiyu-tech" for product "Bf-450m"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2 Firmware
Search vendor "Chiyu-tech" for product "Semac S2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2
Search vendor "Chiyu-tech" for product "Semac S2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1 Firmware
Search vendor "Chiyu-tech" for product "Semac D1 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1
Search vendor "Chiyu-tech" for product "Semac D1"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2
Search vendor "Chiyu-tech" for product "Semac D2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4 Firmware
Search vendor "Chiyu-tech" for product "Semac D4 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4
Search vendor "Chiyu-tech" for product "Semac D4"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3 Firmware
Search vendor "Chiyu-tech" for product "Semac S3v3 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3
Search vendor "Chiyu-tech" for product "Semac S3v3"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 N300 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300
Search vendor "Chiyu-tech" for product "Semac D2 N300"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp Firmware
Search vendor "Chiyu-tech" for product "Semac S1 Osdp Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp
Search vendor "Chiyu-tech" for product "Semac S1 Osdp"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630 Firmware
Search vendor "Chiyu-tech" for product "Bf-630 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630
Search vendor "Chiyu-tech" for product "Bf-630"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631w Firmware
Search vendor "Chiyu-tech" for product "Bf-631w Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631w
Search vendor "Chiyu-tech" for product "Bf-631w"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-830w Firmware
Search vendor "Chiyu-tech" for product "Bf-830w Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-830w
Search vendor "Chiyu-tech" for product "Bf-830w"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Webpass Firmware
Search vendor "Chiyu-tech" for product "Webpass Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Webpass
Search vendor "Chiyu-tech" for product "Webpass"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bfminiw Firmware
Search vendor "Chiyu-tech" for product "Bfminiw Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bfminiw
Search vendor "Chiyu-tech" for product "Bfminiw"
--
Safe