CHIYU.TCP.IP.Converter.Multiple.XSS

description-logoDescription

This indicates an attack attempt against a Cross Site Scripting vulnerability in CHIYU IoT devices.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application while handling maliciously crafted requests. An attacker can exploit this by tricking an unsuspecting user into visiting a malicious webpage and execute arbitrary script code within the context of the users' browser.

affected-products-logoAffected Products

BF-430 all firmware versions prior to June 2021
BF-431 all firmware versions prior to June 2021
BF-450M all firmware versions prior to June 2021
BF-630 all firmware versions prior to June 2021
BF631-W all firmware versions prior to June 2021
BF830-W all firmware versions prior to June 2021
Webpass all firmware versions prior to June 2021
BF-MINI-W all firmware versions prior to June 2021
SEMAC all firmware versions prior to June 2021

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor
https://www.chiyu-tech.com/msg/msg88.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-10-20 18.182 Default_action:pass:drop
2021-08-19 18.143 Sig Added
2021-08-16 18.140