Vulnerability Details CVE-2021-31641
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-31641
-
cpe:2.3:h:chiyu-tech:bf-430:-
-
cpe:2.3:h:chiyu-tech:bf-431:-
-
cpe:2.3:h:chiyu-tech:bf-450m:-
-
cpe:2.3:h:chiyu-tech:bf-630:-
-
cpe:2.3:h:chiyu-tech:bf-631w:-
-
cpe:2.3:h:chiyu-tech:bf-830w:-
-
cpe:2.3:h:chiyu-tech:bfminiw:-
-
cpe:2.3:h:chiyu-tech:semac_d1:-
-
cpe:2.3:h:chiyu-tech:semac_d2:-
-
cpe:2.3:h:chiyu-tech:semac_d2_n300:-
-
cpe:2.3:h:chiyu-tech:semac_d4:-
-
cpe:2.3:h:chiyu-tech:semac_s1_osdp:-
-
cpe:2.3:h:chiyu-tech:semac_s2:-
-
cpe:2.3:h:chiyu-tech:semac_s3v3:-
-
cpe:2.3:h:chiyu-tech:webpass:-
-
cpe:2.3:o:chiyu-tech:bf-430_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-431_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-450m_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-630_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-631w_firmware:-
-
cpe:2.3:o:chiyu-tech:bf-830w_firmware:-
-
cpe:2.3:o:chiyu-tech:bfminiw_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d1_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d2_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d2_n300_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_d4_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s1_osdp_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s2_firmware:-
-
cpe:2.3:o:chiyu-tech:semac_s3v3_firmware:-
-
cpe:2.3:o:chiyu-tech:webpass_firmware:-