CVE-2021-41290
Summary
| CVE | CVE-2021-41290 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-30 11:15:00 UTC |
| Updated | 2022-10-21 17:46:00 UTC |
| Description | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ecoa | Ecs Router Controller-ecs | - | All | All | All |
| Operating System | Ecoa | Ecs Router Controller-ecs Firmware | - | All | All | All |
| Hardware | Ecoa | Riskbuster | - | All | All | All |
| Operating System | Ecoa | Riskbuster Firmware | - | All | All | All |
| Application | Ecoa | Riskterminator | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TWCERT/CC台灣電腦網路危機處理暨協調中心-ECOA BAS controller - Path Traversal-1 | MISC | www.twcert.org.tw | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.