← Vulnerability feed

Vulnerability record · CVE-2021-41291 · published 30 September 2021

CVE-2021-41291: ECOA BAS controller path traversal exposes directory contents

Ecoa · Ecs Router Controller Ecs Firmware

The ECOA BAS controller's File Manager is vulnerable to path traversal via a GET parameter, allowing directory content disclosure. The flaw is remotely reachable without authentication, so exposed controllers leak file and directory listings to anyone who can reach the interface.

7.5 CVSS 3.1 High EPSS 83% · top 0.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.

What it is

The ECOA BAS controller's File Manager is vulnerable to path traversal via a GET parameter, allowing directory content disclosure. The flaw is remotely reachable without authentication, so exposed controllers leak file and directory listings to anyone who can reach the interface.

Impact

An attacker gains read access to directory contents on the affected device, which can reveal file names, paths and configuration details useful for follow-on attacks. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached over the network through the File Manager GET parameter; the CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged beyond a third-party advisory, but EPSS is very high (0.827, 99.6th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the vendor firmware update for the ECOA BAS controller and affected ECS router controller, RiskBuster and RiskTerminator products.
  • Restrict network access to the controller's management interface to trusted management networks or VPN only.
  • Disable or block the File Manager feature if it is not required for operations.
  • Monitor vendor and TW-CERT advisories for updated firmware or workarounds.

Detection

  • Review web server or device logs for GET requests to File Manager endpoints containing traversal sequences such as ../ or encoded variants.
  • Alert on unusual directory-listing responses or repeated file-path requests from single source IPs.
  • Baseline normal File Manager access patterns and flag first-time or external source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41291 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41290Ecoa ecs router controller-ecs firmware unrestricted file upload vulnerabilityECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can r…EPSS 2.3%9.8CVE-2021-41296Ecoa ecs router controller-ecs firmware weak password requirements vulnerabilityECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control o…EPSS 0.95%9.8CVE-2021-41299Ecoa ecs router controller-ecs firmware hard-coded credentials vulnerabilityECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s pri…EPSS 2.1%9.8CVE-2021-41300Ecoa ecs router controller-ecs firmware insufficiently protected credentials vulnerabilityECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain p…EPSS 0.98%9.8CVE-2021-41301Ecoa ecs router controller-ecs firmware information exposure vulnerabilityECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…EPSS 2.0%9.1CVE-2021-41292Ecoa ecs router controller-ecs firmware authentication bypass via alternate path vulnerabilityECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut…EPSS 1.2%9.1CVE-2021-41294Ecoa ecs router controller-ecs firmware path traversal vulnerabilityECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated …EPSS 1.2%8.8CVE-2021-41295Ecoa ecs router controller-ecs firmware cross-site request forgery vulnerabilityECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious we…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2021-41291), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.