nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41294 CVE-2021-41294
CRITICAL
ECOA BAS controller - Path Traversal-4
Record summary
CVE-2021-41294 has a selected CVSS score of 9.1 (critical).
Description
ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario.
Description source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
ECS Router Controller ECS (FLASH)Browse ECOA / ECS Router Controller ECS (FLASH) | CVE List | next of 0 | unknown |
Graphic Control SoftwareBrowse ECOA / Graphic Control Software | CVE List | next of 0 | unknown |
RiskBuster System RB 3.0.0Browse ECOA / RiskBuster System RB 3.0.0 | CVE List | next of 0 | unknown |
RiskBuster System TRANE 1.0Browse ECOA / RiskBuster System TRANE 1.0 | CVE List | next of 0 | unknown |
RiskBuster Terminator E6L45Browse ECOA / RiskBuster Terminator E6L45 | CVE List | next of 0 | unknown |
RiskTerminatorBrowse ECOA / RiskTerminator | CVE List | next of 0 | unknown |
SmartHome II E9246Browse ECOA / SmartHome II E9246 | CVE List | next of 0 | unknown |
References
2twcert.org.tw
https://www.twcert.org.tw/tw/cp-132-5130-7de92-1.html