CVE-2021-41292
—CVSS 3.1
9.1 critical
EPSS
1%p66
Published
()
Modified
Description
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.
- Vendors
- ecoa
- Products
- ecs router controller-ecs firmware, riskbuster firmware, riskterminator
- Weakness
- CWE-288, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.