packetstormsecurity.com
http://packetstormsecurity.com/files/162934/CHIYU-IoT-Denial-Of-Service.html CVE-2021-31642
MEDIUM
CHIYU IoT Devices - Denial of Service (DoS)
Record summary
CVE-2021-31642 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCHIYU IoT Devices - Denial of Service (DoS)ExploitDB exploitby sirpedrotavaresNot analyzed1 file
References
5gitbook.seguranca-informatica.pt
https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-31642 seguranca-informatica.pt
https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks chiyu-tech.com
https://www.chiyu-tech.com/msg/message-Firmware-update-87.html