S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-31682 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Automated Logic WebCTRL/WebCTRL OEM affects v. 6.5 and below.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31682
6.1
CVSS

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Automated Logic WebCTRL/WebCTRL OEM is a web application used for monitoring and controlling HVAC systems in buildings. This product is widely used in commercial buildings to ensure the comfort and safety of occupants through optimized heating, ventilation, and air conditioning. It allows facility managers to remotely control and monitor HVAC equipment, temperature, humidity, and lighting.

CVE-2021-31682 is a vulnerability detected in the Automated Logic WebCTRL/WebCTRL OEM login portal. Due to the operatorlocale GET parameter not being sanitized, reflected XSS attacks can be executed. This vulnerability affects versions 6.5 and below. Attackers can exploit this flaw by injecting malicious code into a GET parameter, which will be reflected back to the user's browser without sanitization.

This vulnerability can lead to a variety of negative consequences when exploited. Attackers can steal sensitive data, such as login credentials, by tricking users into clicking on a malicious link. They can also inject malware, creating a backdoor that allows them unrestricted access to the HVAC system. This can result in significant damage to the building's infrastructure, compromised security, and financial loss.

At s4e.io, we provide a platform that enables users to quickly and easily identify vulnerabilities in their digital assets. Our pro features allow users to perform in-depth vulnerability scans, receive real-time alerts, and access an extensive database of security issues. By leveraging the power of our platform, users can proactively identify and resolve security issues before they become a problem. With s4e.io, you can rest assured that your digital assets are always secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to version 6.6 or above, which includes a fix for this vulnerability.
  • Deploy a web application firewall (WAF) that can detect and block malicious traffic.
  • Implement input validation and output sanitization to prevent XSS attacks.
  • Disable unnecessary features and services to reduce the attack surface.
  • Educate users on how to recognize and avoid phishing attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.