← Back to browse · API

CVE-2021-41290

Severity
CRITICAL
CVSS
9.8
EPSS
0.02322
Risk score
40.01
CISA KEV
No
PoC
No
Published
2021-09-30
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-28320, GHSA-FGX6-CF44-R3H2
Products
-
Sources
euvd EUVD-2021-28320

Description

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.

References