PT-2025-13527 · Unknown · Satech Bcu

Aarón Flecha

·

Publicado

2025-03-28

·

Atualizado

2025-03-28

·

CVE-2025-2864

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SaTECH BCU version 2.1.3
Description The issue allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser, which is a reflected XSS attack.
Recommendations For SaTECH BCU version 2.1.3, consider updating the firmware to a version that addresses this issue, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to sensitive features that may be exploited through the reflected XSS attack.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-2864

Produtos afetados

Satech Bcu