peter bassill · operator
$ cve CVE-2021-31251 JSON

CVE-2021-31251 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 35.7% (pctl 98)

Patch early

A public exploit exists.

Description

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS35.71% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2021-06-04
Last modified2026-06-17

Affected (20)

VendorProduct
chiyu-techbf-430
chiyu-techbf-430 firmware
chiyu-techbf-431
chiyu-techbf-431 firmware
chiyu-techbf-450m
chiyu-techbf-450m firmware
chiyu-techsemac d1
chiyu-techsemac d1 firmware
chiyu-techsemac d2
chiyu-techsemac d2 firmware
chiyu-techsemac d2 n300
chiyu-techsemac d2 n300 firmware
chiyu-techsemac d4
chiyu-techsemac d4 firmware
chiyu-techsemac s1 osdp
chiyu-techsemac s1 osdp firmware
chiyu-techsemac s2
chiyu-techsemac s2 firmware
chiyu-techsemac s3v3
chiyu-techsemac s3v3 firmware

Public exploits

SourceTitleDate
exploit-dbCHIYU IoT Devices - 'Telnet' Authentication Bypass2021-06-03

References

→ the Explorer  ·  watch your stack  ·  NVD