Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2865


SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.


Published

2025-03-28T14:15:21.727

Last Modified

2025-10-10T16:19:01.090

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-942
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System arteche satech_bcu_firmware 2.1.3 Yes
Hardware arteche satech_bcu - No

References