The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device
View the template here CVE-2021-41291.yaml
References:
https://www.twcert.org.tw/en/cp-139-5140-6343c-2.html