Vulnerability record · CVE-2021-41291 · published 30 September 2021
CVE-2021-41291: ECOA BAS controller path traversal exposes directory contents
Ecoa · Ecs Router Controller Ecs Firmware
The ECOA BAS controller's File Manager is vulnerable to path traversal via a GET parameter, allowing directory content disclosure. The flaw is remotely reachable without authentication, so exposed controllers leak file and directory listings to anyone who can reach the interface.
Description
ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote information disclosure with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
The ECOA BAS controller's File Manager is vulnerable to path traversal via a GET parameter, allowing directory content disclosure. The flaw is remotely reachable without authentication, so exposed controllers leak file and directory listings to anyone who can reach the interface.
Impact
An attacker gains read access to directory contents on the affected device, which can reveal file names, paths and configuration details useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network through the File Manager GET parameter; the CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged beyond a third-party advisory, but EPSS is very high (0.827, 99.6th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the vendor firmware update for the ECOA BAS controller and affected ECS router controller, RiskBuster and RiskTerminator products.
- Restrict network access to the controller's management interface to trusted management networks or VPN only.
- Disable or block the File Manager feature if it is not required for operations.
- Monitor vendor and TW-CERT advisories for updated firmware or workarounds.
Detection
- Review web server or device logs for GET requests to File Manager endpoints containing traversal sequences such as ../ or encoded variants.
- Alert on unusual directory-listing responses or repeated file-path requests from single source IPs.
- Baseline normal File Manager access patterns and flag first-time or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5127-3cbd3-1.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-5127-3cbd3-1.html | Third Party Advisory |
Track CVE-2021-41291 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41291), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.