CVE-2021-31251
CRITICALChiyu-tech BF-430/431/450M and SEMAC Firmware - Authentication Bypass via Malformed Telnet Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-31251. PoCs published by sirpedrotavares.
AI-analyzed exploit summary This exploit bypasses telnet authentication on CHIYU IoT devices by sending malformed telnet negotiation packets, allowing an attacker to gain unauthorized shell access. The PoC establishes a connection and provides an interactive shell.
Description
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.
Exploits (1)
This exploit bypasses telnet authentication on CHIYU IoT devices by sending malformed telnet negotiation packets, allowing an attacker to gain unauthorized shell access. The PoC establishes a connection and provides an interactive shell.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H