CVE-2021-41300
CRITICALECOA BAS - Info Disclosure
Title source: llmDescription
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
Scores
CVSS v3
9.8
EPSS
0.0042
EPSS Percentile
61.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (3)
ecoa/ecs_router_controller-ecs_firmware
ecoa/riskbuster_firmware
ecoa/riskterminator
Timeline
Published
Sep 30, 2021
Tracked Since
Feb 18, 2026