Cross-Site Request Forgery in saTECH BCU Firmware
CVE-2025-2863
5.7MEDIUM
What is CVE-2025-2863?
A cross-site request forgery vulnerability exists in the web application of the saTECH BCU firmware version 2.1.3. This security issue allows an unauthenticated local attacker to exploit active administrator sessions, performing unauthorized actions based on the permissions of the logged-in user. Potential exploits may include rebooting the device or modifying user roles and permissions, thereby compromising the integrity and functionality of the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
saTECH BCU 2.1.3
References
CVSS V4
Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
AarĂłn Flecha
Gabriel VĂa Echezarreta
