Chamilo LMS version 1.11.14 suffers from a persistent cross site scripting vulnerability.
46aaae3bca75f14ca4182e929dd60940d30948fc966d3884b3e4d144172812eb
CHIYU IoT devices suffer from an integer overflow denial of service vulnerability. Affected devices include BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC with firmware versions prior to June 2021.
369646f20627c73fcfc4b1175de5a5c27aedb1a01b4addefab4dce955c086e87
Several IoT devices from the CHIYU Technology firm are vulnerable to a flaw that permits bypassing the telnet authentication process due to an overflow during the negotiation of the telnet protocol. Telnet authentication is bypassed by supplying a specially malformed request, and an attacker may force the remote telnet server to believe that the user has already authenticated. Several models are vulnerable, including BF-430, BF-431, BF-450M, and SEMAC with the most recent firmware versions.
781c1db46d4908a42a01a83b90b7f6c823afa8285764c401421aada6d4c0a9d1
CHIYU IoT devices suffer from multiple cross site scripting vulnerabilities. Versions affected include BF-430, BF-431, BF-450M, BF-630, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC.
a0e148bec7337cb5cb6a2196c1eaeb2f732ddeb5e61a399ebf58969e953122ea
CHIYU TCP/IP Converter devices suffers from a crlf injection vulnerability. Versions affected include BF-430, BF-431, and BF-450M.
e7a596a59cae5f2c12a480ba0005a90bec441a27f46a82c5481c45eb383eab21