PT-2020-20316 · Chiyu · Chiyu Bf-430 232/485 Tcp/Ip Converter

Published

2020-02-12

·

Updated

2020-02-18

·

CVE-2020-8839

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CHIYU BF-430 232/485 TCP/IP Converter versions prior to 1.16.00
Description A stored XSS issue was found, as demonstrated by the "/if.cgi" API endpoint, specifically the TF submask field.
Recommendations For versions prior to 1.16.00, update to version 1.16.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/if.cgi" API endpoint to minimize the risk of exploitation. Avoid using the TF submask field in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8839

Affected Products

Chiyu Bf-430 232/485 Tcp/Ip Converter