AirControl 1.4.2 - PreAuth Remote Code Execution
Vulnerability Description
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37052
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 0xd0ff9 vs j3ssie
Affected Vendor
Ubiquiti, Inc.
View all reports →