← Vulnerability feed

Vulnerability record · CVE-2021-31643 · published 1 June 2021

CVE-2021-31643: CHIYU IoT devices stored XSS in if.cgi username parameter

CChiyu Tech · Bf 631 Firmware

Several CHIYU Technology IoT devices (SEMAC, Biosense, BF-630, BF-631, Webpass) fail to sanitize the username parameter in if.cgi, allowing cross-site scripting. An attacker who can supply that parameter can execute script in the context of a victim's browser session on the device's web interface.

5.4 CVSS 3.1 Medium EPSS 88% · top 0.2% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS rates it medium (5.4) and it requires low privileges plus user interaction, though public exploits and a very high EPSS score raise the practical risk.

What it is

Several CHIYU Technology IoT devices (SEMAC, Biosense, BF-630, BF-631, Webpass) fail to sanitize the username parameter in if.cgi, allowing cross-site scripting. An attacker who can supply that parameter can execute script in the context of a victim's browser session on the device's web interface.

Impact

An attacker can run arbitrary script in a victim's browser against the device's web UI, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via the if.cgi endpoint's username parameter (AV:N). The vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated or partially privileged user must be induced to trigger the crafted input.

Exploitation

Public exploit references exist (Packet Storm and third-party advisories tagged Exploit), and EPSS is very high at 0.8845 (99.76th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Apply the vendor firmware update referenced in the CHIYU advisory (message-Firmware-update-87).
  • If patching is not possible, restrict network access to the device web interface to trusted management networks only.
  • Do not expose the affected devices' web UI to the internet; place them behind a firewall or VPN.
  • Validate and encode the username parameter server-side, or deploy a reverse proxy/WAF rule that blocks script payloads to if.cgi.
  • Monitor vendor channels for further firmware releases covering the listed SEMAC, Biosense, BF-630, BF-631 and Webpass models.

Detection

  • Inspect web/proxy logs for requests to if.cgi with script-like content in the username parameter.
  • Alert on unexpected outbound connections or referrer patterns from device management browsers that could indicate script exfiltration.
  • Review device admin sessions for anomalous actions following visits to crafted if.cgi URLs.
  • Track firmware versions of the listed CHIYU models against the vendor advisory to find unpatched units.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-31251Chiyu-tech bf-430 firmware improper authentication vulnerabilityAn authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining …EPSS 36%6.5CVE-2021-31642Chiyu-tech semac s2 firmware integer overflow vulnerabilityA denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630,…EPSS 44%6.1CVE-2021-31252Chiyu-tech bf-430 firmware open redirect vulnerabilityAn open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can…EPSS 29%6.1CVE-2021-31641Chiyu-tech bf-430 firmware cross-site scripting vulnerabilityAn unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W…EPSS 5.1%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed

Source: NIST National Vulnerability Database (record CVE-2021-31643), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.