← Vulnerability feed

Vulnerability record · CVE-2021-41296 · published 30 September 2021

CVE-2021-41296: Ecoa ecs router controller-ecs firmware weak password requirements vulnerability

Ecoa · Ecs Router Controller Ecs Firmware

ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

9.8 CVSS 3.1 Critical EPSS 0.95% · top 40.3% CWE-521 · Weak password requirements
9.8CVSS 3.1 base score, v2 5.0
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41290Ecoa ecs router controller-ecs firmware unrestricted file upload vulnerabilityECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can r…EPSS 2.3%9.8CVE-2021-41299Ecoa ecs router controller-ecs firmware hard-coded credentials vulnerabilityECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s pri…EPSS 2.1%9.8CVE-2021-41300Ecoa ecs router controller-ecs firmware insufficiently protected credentials vulnerabilityECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain p…EPSS 0.98%9.8CVE-2021-41301Ecoa ecs router controller-ecs firmware information exposure vulnerabilityECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…EPSS 2.0%9.1CVE-2021-41292Ecoa ecs router controller-ecs firmware authentication bypass via alternate path vulnerabilityECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass aut…EPSS 1.2%9.1CVE-2021-41294Ecoa ecs router controller-ecs firmware path traversal vulnerabilityECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated …EPSS 1.2%8.8CVE-2021-41295Ecoa ecs router controller-ecs firmware cross-site request forgery vulnerabilityECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious we…EPSS 0.43%8.8CVE-2021-41297Ecoa ecs router controller-ecs firmware insufficiently protected credentials vulnerabilityECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credenti…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2021-41296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.