PT-2026-7908 · Unknown · Airleader Master

Angel Lomeli

·

Publicado

2026-02-12

·

Atualizado

2026-03-03

·

CVE-2026-1358

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Airleader Master versions 6.381 and prior
Description Airleader Master versions 6.381 and prior have a flaw allowing unrestricted file uploads to multiple webpages running with maximum privileges. This could allow an unauthenticated user to achieve remote code execution on the server. This issue affects industrial systems, particularly those managing compressed air, and poses a high risk to critical infrastructure sectors. Multiple reports indicate the potential for exploitation, with some sources describing a trivial path to remote root access.
Recommendations Apply vendor fixes or mitigations for versions prior to and including 6.381. Restrict remote access to the controller interfaces for versions prior to and including 6.381. Segment networks to limit the potential impact of exploitation for versions prior to and including 6.381.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1358

Produtos afetados

Airleader Master