Vulnerability record · CVE-2021-31643 · published 1 June 2021
CVE-2021-31643: CHIYU IoT devices stored XSS in if.cgi username parameter
CChiyu Tech · Bf 631 Firmware
Several CHIYU Technology IoT devices (SEMAC, Biosense, BF-630, BF-631, Webpass) fail to sanitize the username parameter in if.cgi, allowing cross-site scripting. An attacker who can supply that parameter can execute script in the context of a victim's browser session on the device's web interface.
Description
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires low privileges plus user interaction, though public exploits and a very high EPSS score raise the practical risk.
What it is
Several CHIYU Technology IoT devices (SEMAC, Biosense, BF-630, BF-631, Webpass) fail to sanitize the username parameter in if.cgi, allowing cross-site scripting. An attacker who can supply that parameter can execute script in the context of a victim's browser session on the device's web interface.
Impact
An attacker can run arbitrary script in a victim's browser against the device's web UI, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via the if.cgi endpoint's username parameter (AV:N). The vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated or partially privileged user must be induced to trigger the crafted input.
Exploitation
Public exploit references exist (Packet Storm and third-party advisories tagged Exploit), and EPSS is very high at 0.8845 (99.76th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the vendor firmware update referenced in the CHIYU advisory (message-Firmware-update-87).
- If patching is not possible, restrict network access to the device web interface to trusted management networks only.
- Do not expose the affected devices' web UI to the internet; place them behind a firewall or VPN.
- Validate and encode the username parameter server-side, or deploy a reverse proxy/WAF rule that blocks script payloads to if.cgi.
- Monitor vendor channels for further firmware releases covering the listed SEMAC, Biosense, BF-630, BF-631 and Webpass models.
Detection
- Inspect web/proxy logs for requests to if.cgi with script-like content in the username parameter.
- Alert on unexpected outbound connections or referrer patterns from device management browsers that could indicate script exfiltration.
- Review device admin sessions for anomalous actions following visits to crafted if.cgi URLs.
- Track firmware versions of the listed CHIYU models against the vendor advisory to find unpatched units.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162887/CHIYU-IoT-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices#cve-2021-31643 | ExploitThird Party Advisory |
| https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks/ | ExploitThird Party Advisory |
| https://www.chiyu-tech.com/msg/message-Firmware-update-87.html | Vendor Advisory |
| http://packetstormsecurity.com/files/162887/CHIYU-IoT-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices#cve-2021-31643 | ExploitThird Party Advisory |
| https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks/ | ExploitThird Party Advisory |
| https://www.chiyu-tech.com/msg/message-Firmware-update-87.html | Vendor Advisory |
Track CVE-2021-31643 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-31643), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.