CVE-2025-2864: Arteche Satech Bcu Firmware

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).

Affected products

  • Arteche Satech Bcu Firmware: version 2.1.3 only

Published 2025-03-28. Last modified 2026-06-17.