Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15094 | SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS). |
Solution
The vulnerability has been fixed by Arteche in firmware version 2.2.1.
Workaround
No workaround given by the vendor.
Sat, 11 Oct 2025 01:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arteche
Arteche satech Bcu Arteche satech Bcu Firmware |
|
| CPEs | cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:* cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Arteche
Arteche satech Bcu Arteche satech Bcu Firmware |
|
| Metrics |
cvssV3_1
|
Sat, 29 Mar 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS). | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-28T14:32:45.839Z
Reserved: 2025-03-27T10:59:44.731Z
Link: CVE-2025-2864
Updated: 2025-03-28T14:32:42.692Z
Status : Analyzed
Published: 2025-03-28T14:15:21.570
Modified: 2025-10-10T16:31:35.547
Link: CVE-2025-2864
No data.
OpenCVE Enrichment
No data.
EUVD