SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in legitimately.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-03-28 14:15
Updated : 2025-10-10 16:39
NVD link : CVE-2025-2861
Mitre link : CVE-2025-2861
CVE.ORG link : CVE-2025-2861
JSON object : View
Products Affected
arteche
- satech_bcu
- satech_bcu_firmware
CWE
CWE-319
Cleartext Transmission of Sensitive Information
