PT-2026-7908 · Unknown · Airleader Master
Angel Lomeli
·
Publicado
2026-02-12
·
Atualizado
2026-03-03
·
CVE-2026-1358
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Airleader Master versions 6.381 and prior
Description
Airleader Master versions 6.381 and prior have a flaw allowing unrestricted file uploads to multiple webpages running with maximum privileges. This could allow an unauthenticated user to achieve remote code execution on the server. This issue affects industrial systems, particularly those managing compressed air, and poses a high risk to critical infrastructure sectors. Multiple reports indicate the potential for exploitation, with some sources describing a trivial path to remote root access.
Recommendations
Apply vendor fixes or mitigations for versions prior to and including 6.381.
Restrict remote access to the controller interfaces for versions prior to and including 6.381.
Segment networks to limit the potential impact of exploitation for versions prior to and including 6.381.
Correção
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Airleader Master