Back

MEDIUM

Cross-site request forgery (CSRF) vulnerability in saTECH BCU

Published Mar 28, 2025

Description

Cross-site request forgery (CSRF) vulnerability in the web application of saTECH BCU firmware version 2.1.3, which could allow an unauthenticated local attacker to exploit active administrator sessions and perform malicious actions. The malicious actions that can be executed by the attacker depend on the logged-in user, and may include rebooting the device or modifying roles and permissions.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by Arteche in firmware version 2.2.1.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Mar 28, 2025
Updated Mar 28, 2025
Reserved Mar 27, 2025
CISA Vulnrichment
Updated Mar 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Mar 28, 2025
Updated Mar 28, 2025
Exploited since n/a
EUVD-2025-15095