← All CVEs

CVE-2021-31251

critical · 9.8

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

9.8
CVSS
35.7%
EPSS (exploit prob.)
98th
EPSS percentile
2021-06-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
chiyu-techbf-430_firmwareall versions
chiyu-techbf-430all versions
chiyu-techbf-431_firmwareall versions
chiyu-techbf-431all versions
chiyu-techbf-450m_firmwareall versions
chiyu-techbf-450mall versions
chiyu-techsemac_s2_firmwareall versions
chiyu-techsemac_s2all versions
chiyu-techsemac_d1_firmwareall versions
chiyu-techsemac_d1all versions
chiyu-techsemac_d2_firmwareall versions
chiyu-techsemac_d2all versions
chiyu-techsemac_d4_firmwareall versions
chiyu-techsemac_d4all versions
chiyu-techsemac_s3v3_firmwareall versions
chiyu-techsemac_s3v3all versions
chiyu-techsemac_d2_n300_firmwareall versions
chiyu-techsemac_d2_n300all versions
chiyu-techsemac_s1_osdp_firmwareall versions
chiyu-techsemac_s1_osdpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-31251