SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15093 SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
Fixes

Solution

The vulnerability has been fixed by Arteche in firmware version 2.2.1.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arteche
Arteche satech Bcu
Arteche satech Bcu Firmware
Weaknesses CWE-79
CPEs cpe:2.3:h:arteche:satech_bcu:-:*:*:*:*:*:*:*
cpe:2.3:o:arteche:satech_bcu_firmware:2.1.3:*:*:*:*:*:*:*
Vendors & Products Arteche
Arteche satech Bcu
Arteche satech Bcu Firmware
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
Title Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU
Weaknesses CWE-942
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-28T14:32:18.569Z

Reserved: 2025-03-27T10:59:45.540Z

Link: CVE-2025-2865

cve-icon Vulnrichment

Updated: 2025-03-28T14:32:14.515Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-28T14:15:21.727

Modified: 2025-10-10T16:19:01.090

Link: CVE-2025-2865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.