ZeroHour

CVE-2021-41293

CVSS 3.1
7.5 high
EPSS
20%p97
Published
()
Modified
Description

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

Vendors
ecoa
Products
ecs router controller-ecs firmware, riskbuster firmware, riskterminator
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.