nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2862 CVE-2025-2862
MEDIUM
Weak Encoding for Password vulnerability in saTECH BCU
Record summary
CVE-2025-2862 has a selected CVSS score of 6.9 (medium).
Description
SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
saTECH BCUBrowse Arteche / saTECH BCUDefault status: unaffected | CVE List | 2.1.3 | affected |
References
2incibe.es
https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu