.. / CVE-2021-41291

Exploit for ECOA Building Automation System - Directory Traversal Content Disclosure (CVE-2021-41291)

Description:

The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device

Nuclei Template

View the template here CVE-2021-41291.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-41291.yaml
Copy

References:

https://www.twcert.org.tw/en/cp-139-5140-6343c-2.html
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-41291
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5670.php
https://www.twcert.org.tw/tw/cp-132-5127-3cbd3-1.html