CVE-2021-41301
9.8 CRITICALECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GE...
Published: 2021-09-30 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-200, CWE-639
Affected products
| Vendor | Product |
|---|---|
| ecoa | ecs_router_controller-ecs_firmware, riskbuster_firmware, riskterminator |
Description
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2021-41302 — ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely query user passw... (7.3 HIGH)
- CVE-2021-41300 — ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page ... (9.8 CRITICAL)
- CVE-2021-41299 — ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain adminis... (9.8 CRITICAL)
- CVE-2021-41298 — ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects ... (8.8 HIGH)
- CVE-2021-41297 — ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclos... (8.8 HIGH)
Same CWE
- CVE-2026-12117 — Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to ...
- CVE-2026-53863 — OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs (7.1 HIGH)
- CVE-2026-12320 — Information disclosure in the Password Manager component (4.3 MEDIUM)
- CVE-2026-12311 — Information disclosure, sandbox escape in the Security: Process Sandboxing component (4.7 MEDIUM)
- CVE-2026-10780 — The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2 (4.3 MEDIUM)