📦 Ecs Router Controller Ecs Firmware

by Ecoa

🔍 What is Ecs Router Controller Ecs Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-41292

CRITICAL CVSS 9.8 Sep 30, 2021

ECOA BAS controller has an authentication bypass vulnerability where unauthenticated attackers can manipulate cookies to bypass authentication. This allows remote attackers to access sensitive informa...

CVE-2021-41294

CRITICAL CVSS 9.1 Sep 30, 2021

ECOA BAS controller has an unauthenticated path traversal vulnerability that allows remote attackers to delete arbitrary files via a specific GET parameter. This can lead to denial of service by delet...

CVE-2021-41296

CRITICAL CVSS 9.8 Sep 30, 2021

ECOA BAS controllers use weak default administrative credentials that can be easily guessed in remote password attacks, allowing attackers to gain full control of the system. This affects all systems ...

CVE-2021-41299

CRITICAL CVSS 9.8 Sep 30, 2021

ECOA BAS controllers contain hard-coded credentials in their Linux distribution image, allowing remote attackers to gain administrator privileges without authentication. This affects all systems runni...

CVE-2021-41301

CRITICAL CVSS 9.8 Sep 30, 2021

The ECOA BAS controller has an insecure direct object reference vulnerability that allows unauthenticated attackers to access configuration files via HTTP GET requests. This exposes sensitive informat...

CVE-2021-41291

HIGH CVSS 7.5 Sep 30, 2021

CVE-2021-41291 is a path traversal vulnerability in ECOA BAS controllers that allows unauthenticated attackers to remotely disclose directory contents via the File Manager's GET parameter. This affect...

CVE-2021-41298

HIGH CVSS 8.8 Sep 30, 2021

The ECOA BAS controller has an insecure direct object reference vulnerability that allows authenticated users to bypass authorization and access hidden system resources. Attackers with general user pr...