The ECOA BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device
id: CVE-2021-41291
info:
name: ECOA Building Automation System - Directory Traversal Content Disc
...