漏洞描述
CHIYU BF-430, BF-431 and BF-450M TCP/IP Converter devices contain a cross-site scripting vulnerability due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, and ppp.cgi.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.chiyu-tech.comhttps://www.chiyu-tech.com/msg/message-Firmware-update-87.htm↗seguranca-informatica.pthttps://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-31250↗github.comhttps://github.com/ARPSyndicate/cvemon↗