ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5126-ca315-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-09-30T10:40:49.516786Z
Updated: 2024-09-16T22:25:25.496Z
Reserved: 2021-09-15T00:00:00
Link: CVE-2021-41290
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-30T11:15:07.357
Modified: 2024-11-21T06:25:58.507
Link: CVE-2021-41290
Redhat
No data.