// For flags

CVE-2021-31643

CHIYU IoT Cross Site Scripting

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

Se presenta una vulnerabilidad de tipo XSS en varios dispositivos IoT de CHIYU Technology, incluyendo SEMAC, Biosense, BF-630, BF-631 y Webpass, debido a una falta de sanitización en el component if.cgi - parámetro username

CHIYU IoT devices suffer from multiple cross site scripting vulnerabilities. Versions affected include BF-430, BF-431, BF-450M, BF-630, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-23 CVE Reserved
  • 2021-06-01 CVE Published
  • 2021-06-01 First Exploit
  • 2024-08-03 CVE Updated
  • 2025-02-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631 Firmware
Search vendor "Chiyu-tech" for product "Bf-631 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-631
Search vendor "Chiyu-tech" for product "Bf-631"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630 Firmware
Search vendor "Chiyu-tech" for product "Bf-630 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Bf-630
Search vendor "Chiyu-tech" for product "Bf-630"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2 Firmware
Search vendor "Chiyu-tech" for product "Semac S2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S2
Search vendor "Chiyu-tech" for product "Semac S2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1 Firmware
Search vendor "Chiyu-tech" for product "Semac D1 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D1
Search vendor "Chiyu-tech" for product "Semac D1"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2
Search vendor "Chiyu-tech" for product "Semac D2"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4 Firmware
Search vendor "Chiyu-tech" for product "Semac D4 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D4
Search vendor "Chiyu-tech" for product "Semac D4"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3 Firmware
Search vendor "Chiyu-tech" for product "Semac S3v3 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S3v3
Search vendor "Chiyu-tech" for product "Semac S3v3"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300 Firmware
Search vendor "Chiyu-tech" for product "Semac D2 N300 Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac D2 N300
Search vendor "Chiyu-tech" for product "Semac D2 N300"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp Firmware
Search vendor "Chiyu-tech" for product "Semac S1 Osdp Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Semac S1 Osdp
Search vendor "Chiyu-tech" for product "Semac S1 Osdp"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Webpass Firmware
Search vendor "Chiyu-tech" for product "Webpass Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Webpass
Search vendor "Chiyu-tech" for product "Webpass"
--
Safe
Chiyu-tech
Search vendor "Chiyu-tech"
Biosense Firmware
Search vendor "Chiyu-tech" for product "Biosense Firmware"
--
Affected
in Chiyu-tech
Search vendor "Chiyu-tech"
Biosense
Search vendor "Chiyu-tech" for product "Biosense"
--
Safe