CVE-2021-41300

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-5136-3e315-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ecoa:ecs_router_controller-ecs:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ecoa:riskbuster_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ecoa:riskbuster:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:ecoa:riskterminator:-:*:*:*:*:*:*:*

History

07 Oct 2021, 14:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : 5.0
v3 : 9.8
References (MISC) https://www.twcert.org.tw/tw/cp-132-5136-3e315-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-5136-3e315-1.html - Third Party Advisory
CPE cpe:2.3:a:ecoa:riskterminator:-:*:*:*:*:*:*:*
cpe:2.3:h:ecoa:riskbuster:-:*:*:*:*:*:*:*
cpe:2.3:o:ecoa:riskbuster_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:ecoa:ecs_router_controller-ecs_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ecoa:ecs_router_controller-ecs:-:*:*:*:*:*:*:*

30 Sep 2021, 11:39

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-30 11:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-41300

Mitre link : CVE-2021-41300

CVE.ORG link : CVE-2021-41300


JSON object : View

Products Affected

ecoa

  • riskterminator
  • riskbuster
  • riskbuster_firmware
  • ecs_router_controller-ecs
  • ecs_router_controller-ecs_firmware
CWE
CWE-522

Insufficiently Protected Credentials