Vulnerability record · CVE-2021-46417 · published 7 April 2022
CVE-2021-46417: Franklin Fueling Colibri Controller path traversal in download function
Franklinfueling · Colibri Firmware
The Colibri Controller Module 1.8.19.8580 handles a download function insecurely, allowing path traversal that discloses internal files. Because the traversal runs with root privileges, exposed files can include sensitive system data. The flaw is remotely reachable without authentication or user interaction.
Description
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with root-level read access and a very high EPSS score, though no confirmed in-the-wild exploitation is listed.
What it is
The Colibri Controller Module 1.8.19.8580 handles a download function insecurely, allowing path traversal that discloses internal files. Because the traversal runs with root privileges, exposed files can include sensitive system data. The flaw is remotely reachable without authentication or user interaction.
Impact
An unauthenticated attacker can read arbitrary internal files from the controller, including files accessible only to root, exposing configuration, credentials or other sensitive data.
Attack surface
Reachable over the network through the vulnerable download function, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but public exploit references exist and EPSS is 0.59753 (99th percentile), indicating a high likelihood of attempted exploitation.
What to do
- Apply the vendor patch or fixed firmware for the Colibri Controller Module; if none is available, isolate affected devices.
- Restrict network access to the controller's management/download interface to trusted hosts only.
- Run the controller with least privilege where possible, since the traversal executes as root.
- Monitor vendor advisories for updated firmware and replacement guidance.
Detection
- Review controller and web server logs for download requests containing path traversal sequences such as ../ or encoded variants.
- Alert on unexpected access to sensitive files (for example /etc/passwd or configuration files) from the controller.
- Monitor network traffic to the controller's download endpoint for anomalous or repeated file retrieval attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166610/FFS-Colibri-Controller-Module-1.8.19.8580-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/166671/Franklin-Fueling-Systems-Colibri-Controller-Module-1.8.19.8580-Local-File-In | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/drive/folders/1Yu4aVDdrgvs-F9jP3R8Cw7qo_TC7VB-R | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166610/FFS-Colibri-Controller-Module-1.8.19.8580-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/166671/Franklin-Fueling-Systems-Colibri-Controller-Module-1.8.19.8580-Local-File-In | ExploitThird Party AdvisoryVDB Entry |
| https://drive.google.com/drive/folders/1Yu4aVDdrgvs-F9jP3R8Cw7qo_TC7VB-R | ExploitThird Party Advisory |
Track CVE-2021-46417 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-46417), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.