S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41293 Scanner

Detects 'Path Traversal' vulnerability in ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, RiskTerminator affects v. Unknown.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41293
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ECS Router Controller ECS (FLASH)by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster Terminator E6L45by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster System RB 3.0.0by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
RiskBuster System TRANE 1.0by ECOA
AFFECTED< unspecifiedSAFE ✓≥ unspecified
Updated Aug 21, 2026View on NVD →
Detail

ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, and RiskTerminator are all controllers and software systems used in various applications such as smart homes, building automation, and enterprise IT infrastructure. These products are designed to provide efficient and reliable control of various systems, including heating, ventilation, and air conditioning.

The CVE-2021-41293 vulnerability detected in these products is a path traversal vulnerability. This vulnerability allows unauthenticated attackers to remotely access arbitrary files on the affected device. By exploiting this vulnerability, attackers can obtain sensitive information such as system configuration files or user credentials.

When exploited, the CVE-2021-41293 vulnerability can lead to severe consequences, such as the compromise of critical systems, data breaches, and financial losses. Attackers can exploit this vulnerability to obtain confidential and sensitive information that can be used for malicious purposes like identity fraud or extortion. This vulnerability can also be used to facilitate other types of attacks such as SQL injections or cross-site scripting attacks.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities like CVE-2021-41293. The platform provides up-to-date information on vulnerabilities, exploits, and security patches, as well as detailed analyses and recommendations for mitigating threats. By using s4e.io, users can stay informed about the latest threats and take proactive steps to secure their systems and data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users of these products take the following precautions:

  • Apply patches or updates provided by the vendor to mitigate the vulnerability.
  • Restrict access to the affected systems to trusted networks or users.
  • Monitor network traffic for any suspicious activity and implement intrusion detection and prevention mechanisms.
  • Encrypt sensitive data transmitted over the network.
  • Limit the exposure of the affected systems to the public Internet.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-41293 scanner - Path Traversal vulnerability in ECOA ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB, RiskBuster System TRANE, Graphic Control Software, SmartHome II E9246, RiskTerminator | S4E