CVE-2021-41300

CRITICAL

ECOA BAS - Info Disclosure

Title source: llm

Description

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 61.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (3)

ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator

Timeline

Published Sep 30, 2021
Tracked Since Feb 18, 2026