SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
10 Oct 2025, 16:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:* cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
References | () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu - Third Party Advisory | |
First Time |
Arteche satech Bcu
Arteche satech Bcu Firmware Arteche |
|
Summary |
|
28 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-28 14:15
Updated : 2025-10-10 16:31
NVD link : CVE-2025-2864
Mitre link : CVE-2025-2864
CVE.ORG link : CVE-2025-2864
JSON object : View
Products Affected
arteche
- satech_bcu_firmware
- satech_bcu
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')