Record summary

CVE-2021-41290 has a selected CVSS score of 9.8 (critical).

Description

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

Description source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus

ECS Router Controller ECS (FLASH)

Browse ECOA / ECS Router Controller ECS (FLASH)
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown
CVE Listnext of 0unknown

References

2