Record summary

CVE-2021-31249 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMCHIYU TCP/IP Converter - Carriage Return Line Feed InjectionCVSS 6.5

CHIYU TCP/IP Converter BF-430, BF-431, and BF-450 are susceptible to carriage return line feed injection. The redirect= parameter, available on multiple CGI components, is not properly validated, thus enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can lead to remote code execution, unauthorized access, or data manipulation.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the vulnerability.

WeaknessesCWE-74
Authorsgeeknik
Template tagscve2021cvechiyucrlfiotchiyu-techvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CPE: cpe:2.3:o:chiyu-tech:bf-430_firmware:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4