CVE-2021-41290

CRITICAL

ECOA BAS controller - Path Traversal

Title source: llm
STIX 2.1

Description

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5126-ca315-1.html

Scores

CVSS v3 9.8
EPSS 0.0197
EPSS Percentile 83.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-434
Status published
Products (3)
ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator
Published Sep 30, 2021
Tracked Since Feb 18, 2026