Chiyu Tech's vulnerability footprint centers on a narrow range of industrial networking and control products, including the BF-430 and BF-431 device families and the SEMAC D2 platform, which occupy specialized roles in embedded and automation environments. The recurring signals reflect the embedded firmware and networking focus of these products, with disclosed issues spanning input validation and access-control patterns typical of devices in this class. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chiyu Tech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31250MEDIUM Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on | Jun 4, 2021 | 5.4 | 72 | NO | YES |
CVE-2021-31643MEDIUM An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.c | Jun 1, 2021 | 5.4 | 65 | NO | NO |
CVE-2021-31251CRITICAL An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with th | Jun 4, 2021 | 9.8 | 59 | NO | YES |
CVE-2021-31642MEDIUM A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnera | Jun 1, 2021 | 6.5 | 53 | NO | YES |
CVE-2021-31249MEDIUM A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= av | Jun 4, 2021 | 6.5 | 40 | NO | YES |
CVE-2021-31252MEDIUM An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link | Jun 4, 2021 | 6.1 | 34 | NO | NO |
CVE-2021-31641MEDIUM An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC | Jun 1, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chiyu Tech.
Media articles that mention a CVE ID that affects a product developed by Chiyu Tech — matched by CVE ID, not by vendor name.