Vulnerabilities > Chiyutw

DATE CVE VULNERABILITY TITLE RISK
2015-08-01 CVE-2015-5618 Permissions, Privileges, and Access Controls vulnerability in Chiyutw Bf-630 and Bf-630W
Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time Set configuration settings via a request to voice.htm or (b) UniFinger configuration settings via a request to bf.htm, a different vulnerability than CVE-2015-2871.
network
low complexity
chiyutw CWE-264
7.5
2015-08-01 CVE-2015-2870 Cross-site Scripting vulnerability in Chiyutw Bf-630, Bf-630W and Bf-660C
Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.
network
chiyutw CWE-79
4.3