<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:42:40.168352+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2021-41301</id>
    <title>CVE-2021-41301 — ECOA BAS controller - Exposure of Sensitive Information to an Unauthorized Actor</title>
    <updated>2026-10-05T20:42:40.185451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> ECOA ECS Router Controller ECS (FLASH), ECOA RiskBuster Terminator E6L45, ECOA RiskBuster System RB 3.0.0, ECOA RiskBuster System TRANE 1.0, ECOA Graphic Control Software, ECOA SmartHome II E9246, ECOA RiskTerminator</p>
<p>ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2021-41301"/>
  </entry>
</feed>
