5
CVSSv2

CVE-2021-41291

Published: 30/09/2021 Updated: 07/10/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ecoa ecs_router_controller-ecs_firmware -

ecoa riskbuster_firmware -

ecoa riskterminator -