KEVIntel
7.5
CVSS
High

CVE-2021-41293

PUBLISHED

ECOA BAS controller - Path Traversal-3

Not yet in CISA KEV

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
ECOA
Product
ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB 3.0.0, RiskBuster System TRANE 1.0, Graphic Control Software, SmartHome II E9246, RiskTerminator
Published
Sep 30, 2021
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

nuclei_scanner

Weaknesses (CWE)

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS Scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Status

Exploited in the wild

Recorded 2025-06-20 00:00:00 UTC · The Shadowserver (via CIRCL)

Proof of concept available

Recorded 2026-06-12 14:20:24 UTC · Nuclei Templates

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) First 2025-06-20 00:00 UTC

Scanner Integrations

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

CVE-2021-41293

nuclei · Created Unknown

Timeline

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei

  • CVE Published to Public

  • CVE ID Reserved