CVE-2021-41296

CRITICAL

ECOA BAS - Info Disclosure

Title source: llm
STIX 2.1

Description

ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

Scores

CVSS v3 9.8
EPSS 0.0023
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-521
Status published
Products (3)
ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator
Published Sep 30, 2021
Tracked Since Feb 18, 2026