CVE-2021-46417 describes a critical path traversal vulnerability in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580, allowing unauthorized disclosure of internal files with root privileges due to insecure handling of a download function. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this vulnerability can be exploited remotely without authentication, leading to significant data compromise. While not currently on CISA's KEV catalog, public exploit code exists, including a Metasploit module and Nuclei templates, yet it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.19.8580CPE matchmatch criteria | cpe:2.3:o:franklinfueling:colibri_firmware:1.8.19.8580:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.