S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-41291

7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
ecs router controller ecs (flash)riskbuster terminator e6l45riskbuster system rb 3.0.0riskbuster system trane 1.0graphic control softwaresmarthome ii e9246
Updated Sep 22, 2026View on NVD →
S4E scanner

CVE-2021-41291 Scanner

Detects 'Path Traversal' vulnerability in ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, RiskTerminator affects v. Unknown.

Used 2.5k times · 5.9k assets checked · domain, ipv4, subdomain

CVE history: ecs router controller ecs (flash)

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →