ZeroHour

CVE-2021-41290

CVSS 3.1
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

Vendors
ecoa
Products
ecs router controller-ecs firmware, riskbuster firmware, riskterminator
Weakness
CWE-434, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.