← Vulnerability feed

Vulnerability record · CVE-2021-41295 · published 30 September 2021

CVE-2021-41295: Ecoa ecs router controller-ecs firmware cross-site request forgery vulnerability

Ecoa · Ecs Router Controller Ecs Firmware

ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.

8.8 CVSS 3.1 High EPSS 0.43% · top 65.4% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41290Ecoa ecs router controller-ecs firmware unrestricted file upload vulnerabilityECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can r…EPSS 2.3%9.8CVE-2021-41296Ecoa ecs router controller-ecs firmware weak password requirements vulnerabilityECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control o…EPSS 0.95%9.8CVE-2021-41299Ecoa ecs router controller-ecs firmware hard-coded credentials vulnerabilityECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s pri…EPSS 2.1%9.8CVE-2021-41300Ecoa ecs router controller-ecs firmware insufficiently protected credentials vulnerabilityECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain p…EPSS 0.98%9.8CVE-2021-41301Ecoa ecs router controller-ecs firmware information exposure vulnerabilityECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…EPSS 2.0%9.1CVE-2021-41292Ecoa ecs router controller-ecs firmware authentication bypass via alternate path vulnerabilityECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut…EPSS 1.2%9.1CVE-2021-41294Ecoa ecs router controller-ecs firmware path traversal vulnerabilityECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated …EPSS 1.2%8.8CVE-2021-41297Ecoa ecs router controller-ecs firmware insufficiently protected credentials vulnerabilityECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credenti…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2021-41295), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.