CVE-2021-41293
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.
7.5
CVSS
19.9%
EPSS (exploit prob.)
97th
EPSS percentile
2021-09-30
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ecoa | ecs_router_controller-ecs_firmware | all versions |
| ecoa | ecs_router_controller-ecs | all versions |
| ecoa | riskbuster_firmware | all versions |
| ecoa | riskbuster | all versions |
| ecoa | riskterminator | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-41293