name:ECOA Building Automation System - Directory Traversal Content Disclosure
author:gy741
severity:high
description:The BAS controller suffers from a directory traversal content disclosure vulnerability. Using the GET parameter cpath in File Manager (fmangersub), attackers can disclose directory content on the affected device