PT-2020-16431 · Apache+1 · Tomcat Manager+1

Daniel Isern

+1

·

Published

2020-11-16

·

Updated

2021-07-21

·

CVE-2020-26510

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airleader Master versions <= 6.21
Description The issue allows remote code execution due to default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file.
Recommendations For Airleader Master versions <= 6.21, change the default credentials to secure ones and restrict access to the Tomcat Manager to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26510

Affected Products

Airleader Master
Tomcat Manager