QSearchQSearch

CVE-2021-41292

9.8 CRITICAL

ECOA BAS controller suffers from an authentication bypass vulnerability

Published: 2021-09-30 · Last updated: 2026-06-17

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-287, CWE-288

Affected products

VendorProduct
ecoaecs_router_controller-ecs_firmware, riskbuster_firmware, riskterminator

Description

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-41302 ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user passw... (7.3 HIGH)
  • CVE-2021-41301 ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GE... (9.8 CRITICAL)
  • CVE-2021-41300 ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page ... (9.8 CRITICAL)
  • CVE-2021-41299 ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain adminis... (9.8 CRITICAL)
  • CVE-2021-41298 ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects ... (8.8 HIGH)

Same CWE

  • CVE-2026-48780 Forem is open source software for building communities (8.2 HIGH)
  • CVE-2026-12225 syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability
  • CVE-2026-49764 Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions (9.8 CRITICAL)
  • CVE-2026-48970 Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions (8.1 HIGH)
  • CVE-2026-42668 Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions (7.5 HIGH)