CVE-2021-41292
9.8 CRITICALECOA BAS controller suffers from an authentication bypass vulnerability
Published: 2021-09-30 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-287, CWE-288
Affected products
| Vendor | Product |
|---|---|
| ecoa | ecs_router_controller-ecs_firmware, riskbuster_firmware, riskterminator |
Description
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2021-41302 — ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user passw... (7.3 HIGH)
- CVE-2021-41301 — ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GE... (9.8 CRITICAL)
- CVE-2021-41300 — ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page ... (9.8 CRITICAL)
- CVE-2021-41299 — ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain adminis... (9.8 CRITICAL)
- CVE-2021-41298 — ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects ... (8.8 HIGH)
Same CWE
- CVE-2026-48780 — Forem is open source software for building communities (8.2 HIGH)
- CVE-2026-12225 — syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability
- CVE-2026-49764 — Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions (9.8 CRITICAL)
- CVE-2026-48970 — Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions (8.1 HIGH)
- CVE-2026-42668 — Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions (7.5 HIGH)