← Back

Chiyu Tech

chiyu-tech

7 CVEs • 34 products

Products (34)

Click to collapse
Toggle
Bf 430
bf-430
Bf 431
bf-431
Bf 450m
bf-450m
Semac S2
semac_s2
Semac D1
semac_d1
Semac D2
semac_d2
Semac D4
semac_d4
Semac S3v3
semac_s3v3
Semac D2 N300
semac_d2_n300
Semac S1 Osdp
semac_s1_osdp
Bf 630
bf-630
Bf 631w
bf-631w
Bf 830w
bf-830w
Webpass
webpass
Bfminiw
bfminiw
Bf 631
bf-631
Biosense
biosense

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chiyu Tech
14Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+11 more
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to con...Show more
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.Show less
1Chiyu Tech
10Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+7 more
Jun 17, 2026
Jun 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially...Show more
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.Show less
1Chiyu Tech
3Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cg...Show more
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi.Show less
1Chiyu Tech
3Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.
1Chiyu Tech
11Bf 630 Firmware
Bf 631 FirmwareBiosense Firmware+8 more
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
1Chiyu Tech
11Bf 630 Firmware
Bf 631 FirmwareBiosense Firmware+8 more
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an une...Show more
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.Show less
1Chiyu Tech
15Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+12 more
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the...Show more
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.Show less