CVE-2025-2865

SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:*
cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-28 14:15

Updated : 2025-10-10 16:19


NVD link : CVE-2025-2865

Mitre link : CVE-2025-2865

CVE.ORG link : CVE-2025-2865


JSON object : View

Products Affected

arteche

  • satech_bcu
  • satech_bcu_firmware
CWE
CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')