CVE-2021-41294

CRITICAL

ECOA BAS controller - Path Traversal

Title source: llm
STIX 2.1

Description

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5130-7de92-1.html

Scores

CVSS v3 9.1
EPSS 0.0115
EPSS Percentile 62.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-22
Status published
Products (3)
ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator
Published Sep 30, 2021
Tracked Since Feb 18, 2026