← All CVEs

CVE-2021-31252

medium · 6.1

An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.

6.1
CVSS
28.6%
EPSS (exploit prob.)
98th
EPSS percentile
2021-06-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-601

Affected products

VendorProductAffected versions
chiyu-techbf-430_firmwareall versions
chiyu-techbf-430all versions
chiyu-techbf-431_firmwareall versions
chiyu-techbf-431all versions
chiyu-techbf-450m_firmwareall versions
chiyu-techbf-450mall versions
chiyu-techsemac_s2_firmwareall versions
chiyu-techsemac_s2all versions
chiyu-techsemac_d1_firmwareall versions
chiyu-techsemac_d1all versions
chiyu-techsemac_d2_firmwareall versions
chiyu-techsemac_d2all versions
chiyu-techsemac_d4_firmwareall versions
chiyu-techsemac_d4all versions
chiyu-techsemac_s3v3_firmwareall versions
chiyu-techsemac_s3v3all versions
chiyu-techsemac_d2_n300_firmwareall versions
chiyu-techsemac_d2_n300all versions
chiyu-techsemac_s1_osdp_firmwareall versions
chiyu-techsemac_s1_osdpall versions
chiyu-techbf-630_firmwareall versions
chiyu-techbf-630all versions
chiyu-techbf-631w_firmwareall versions
chiyu-techbf-631wall versions
chiyu-techbf-830w_firmwareall versions
chiyu-techbf-830wall versions
chiyu-techwebpass_firmwareall versions
chiyu-techwebpassall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-31252