CVE-2021-41290
9.8 CRITICALECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability
Published: 2021-09-30 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-22, CWE-434
Affected products
| Vendor | Product |
|---|---|
| ecoa | ecs_router_controller-ecs_firmware, riskbuster_firmware, riskterminator |
Description
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2021-41302 — ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user passw... (7.3 HIGH)
- CVE-2021-41301 — ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GE... (9.8 CRITICAL)
- CVE-2021-41300 — ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page ... (9.8 CRITICAL)
- CVE-2021-41299 — ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain adminis... (9.8 CRITICAL)
- CVE-2021-41298 — ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects ... (8.8 HIGH)
Same CWE
- CVE-2026-48777 — FileBrowser Quantum is a free, self-hosted, web-based file manager
- CVE-2026-40750 — Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server (9.9 CRITICAL)
- CVE-2026-8442 — The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8 (8.1 HIGH)
- CVE-2026-6933 — The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and inclu... (8.8 HIGH)
- CVE-2026-49766 — Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions (9.9 CRITICAL)