VulnerabilityModified
CVE-2021-41290
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability.
CRITICAL 9.8EPSS 2.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.32% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434, CWE-22
- Affected
- ecoa/ecs router controller-ecs firmware · ecoa/riskbuster firmware · ecoa/riskterminator
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-5126-ca315-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-5126-ca315-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.