Unrated severityNVD Advisory· Published Mar 28, 2025· Updated Mar 28, 2025
Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU
CVE-2025-2864
Description
SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).
Affected products
2- Arteche/saTECH BCUv5Range: 2.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.