SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15094 SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
Fixes

Solution

The vulnerability has been fixed by Arteche in firmware version 2.2.1.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Arteche
Arteche satech Bcu
Arteche satech Bcu Firmware
CPEs cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:*
cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:*
Vendors & Products Arteche
Arteche satech Bcu
Arteche satech Bcu Firmware
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
Title Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-28T14:32:45.839Z

Reserved: 2025-03-27T10:59:44.731Z

Link: CVE-2025-2864

cve-icon Vulnrichment

Updated: 2025-03-28T14:32:42.692Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-28T14:15:21.570

Modified: 2025-10-10T16:31:35.547

Link: CVE-2025-2864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.