CVE-2021-41296

CRITICAL

ECOA BAS Controller - Weak Default Administrative Credentials

Title source: llm
STIX 2.1

Description

ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5132-65705-1.html

Scores

CVSS v3 9.8
EPSS 0.0092
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-521
Status published
Products (3)
ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator
Published Sep 30, 2021
Tracked Since Feb 18, 2026