VYPR
Unrated severityNVD Advisory· Published Mar 28, 2025· Updated Apr 3, 2025

Cleartext Transmission of Sensitive Information vulnerability in saTECH BCU

CVE-2025-2861

Description

SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in legitimately.

Affected products

2
  • SaTECH/BCUllm-fuzzy
    Range: =2.1.3
  • Arteche/saTECH BCUv5
    Range: 2.1.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.