CVE-2021-31249
CHIYU TCP/IP Converter - Carriage Return Line Feed Injection
Record summary
CVE-2021-31249 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMCHIYU TCP/IP Converter - Carriage Return Line Feed InjectionCVSS 6.5
CHIYU TCP/IP Converter BF-430, BF-431, and BF-450 are susceptible to carriage return line feed injection. The redirect= parameter, available on multiple CGI components, is not properly validated, thus enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability can lead to remote code execution, unauthorized access, or data manipulation.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the vulnerability.
Source: ProjectDiscovery