CVE-2025-2864

SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:*
cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:*

History

10 Oct 2025, 16:31

Type Values Removed Values Added
First Time Arteche satech Bcu Firmware
Arteche
Arteche satech Bcu
Summary
  • (es) SaTECH BCU, en su versión de firmware 2.1.3, permite a un atacante inyectar código malicioso en el sitio web legítimo del dispositivo afectado, una vez establecida la cookie. Este ataque solo afecta al navegador de la víctima (XSS reflejado).
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:*
cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:*

28 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 14:15

Updated : 2025-10-10 16:31


NVD link : CVE-2025-2864

Mitre link : CVE-2025-2864

CVE.ORG link : CVE-2025-2864


JSON object : View

Products Affected

arteche

  • satech_bcu
  • satech_bcu_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')