vendor:
BF-430, BF-431, and BF-450M TCP/IP Converter devices
by:
sirpedrotavares
6.5
CVSS
MEDIUM
CRLF injection
20
CWE
Product Name: BF-430, BF-431, and BF-450M TCP/IP Converter devices
Affected Version From: all firmware versions < June 2021
Affected Version To: all firmware versions < June 2021
Patch Exists: YES
Related CWE: CVE-2021-31249
CPE: 2.3:a:chiyu_technology_inc:bf-430;bf-431;bf-450m_tcp/ip_converter_devices
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: BF-430, BF-431, and BF-450M
2021
CHIYU TCP/IP Converter devices – CRLF injection
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.
Mitigation:
Validate the parameter redirect= before processing the request.