S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41291 Scanner

Detects 'Path Traversal' vulnerability in ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, RiskTerminator affects v. Unknown.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41291
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ECS Router Controller ECS (FLASH)by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster Terminator E6L45by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster System RB 3.0.0by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster System TRANE 1.0by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Updated Aug 19, 2026View on NVD →
Detail

The ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, and RiskTerminator are all products used for controlling and managing various systems in a building, such as HVAC, lighting, and security. These products are commonly used in commercial buildings and aim to provide efficient and effective control over all building systems through a central interface. They are known for their reliability, ease of use, and flexibility in configuring and managing different systems.

CVE-2021-41291 is a path traversal vulnerability found in the ECOA BAS controller. This vulnerability allows unauthenticated attackers to remotely disclose directory content on the system through the use of the File Manager's GET parameter. Essentially, this means that attackers can access and view sensitive information, such as configuration files and system logs, without the need for valid credentials. This vulnerability can be particularly concerning for commercial buildings, as it can expose private information related to building management and therefore pose a significant security risk.

When exploited, this vulnerability can lead to sensitive information being disclosed to unauthorized individuals. Attackers can gain access to login credentials, configuration files, and sensitive system information, which can be used to track building activities, compromise system configurations, and perform other malicious activities. This can result in significant financial losses, damage to the reputation of the organization, and even legal consequences if any laws or regulations were violated as a result of the exploitation.

With the Pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities like CVE-2021-41291. They can receive alerts about the latest threats and vulnerabilities, access expert analysis and recommendations, and gain insight into the latest security trends. This way, they can stay informed and take proactive measures to protect their systems and data from potential attacks.

 

REFERENCES

Solution Advice

To mitigate the risks posed by CVE-2021-41291, security precautions should be taken, including:

  • Install security patches provided by the vendor or manufacturer of the affected product.
  • Implement access controls to limit the amount of information exposed during the exploitation of this vulnerability.
  • Ensure that strong passwords are being used to secure all accounts with access to the affected product.
  • Enforce strict access controls for system resources, such as files and directories, to ensure that only authorized users have access to sensitive information.
  • Train employees and other users on security best practices and how to identify and report potential security threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.