← Back to browse · API

CVE-2021-41291

Severity
HIGH
CVSS
7.5
EPSS
0.82274
Risk score
58.8
CISA KEV
No
PoC
No
Published
2021-09-30
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-28321, GHSA-9V2M-X295-3G46
Products
-
Sources
euvd EUVD-2021-28321

Description

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

References