nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41290 CVE-2021-41290
CRITICAL
ECOA BAS controller - Path Traversal-1
Record summary
CVE-2021-41290 has a selected CVSS score of 9.8 (critical).
Description
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.
Description source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
ECS Router Controller ECS (FLASH)Browse ECOA / ECS Router Controller ECS (FLASH) | CVE List | next of 0 | unknown |
Graphic Control SoftwareBrowse ECOA / Graphic Control Software | CVE List | next of 0 | unknown |
RiskBuster System RB 3.0.0Browse ECOA / RiskBuster System RB 3.0.0 | CVE List | next of 0 | unknown |
RiskBuster System TRANE 1.0Browse ECOA / RiskBuster System TRANE 1.0 | CVE List | next of 0 | unknown |
RiskBuster Terminator E6L45Browse ECOA / RiskBuster Terminator E6L45 | CVE List | next of 0 | unknown |
RiskTerminatorBrowse ECOA / RiskTerminator | CVE List | next of 0 | unknown |
SmartHome II E9246Browse ECOA / SmartHome II E9246 | CVE List | next of 0 | unknown |
References
2twcert.org.tw
https://www.twcert.org.tw/tw/cp-132-5126-ca315-1.html