PT-2026-7908 · Unknown · Airleader Master

Angel Lomeli

·

Published

2026-02-12

·

Updated

2026-03-03

·

CVE-2026-1358

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Airleader Master versions 6.381 and prior
Description Airleader Master versions 6.381 and prior have a flaw allowing unrestricted file uploads to multiple webpages running with maximum privileges. This could allow an unauthenticated user to achieve remote code execution on the server. This issue affects industrial systems, particularly those managing compressed air, and poses a high risk to critical infrastructure sectors. Multiple reports indicate the potential for exploitation, with some sources describing a trivial path to remote root access.
Recommendations Apply vendor fixes or mitigations for versions prior to and including 6.381. Restrict remote access to the controller interfaces for versions prior to and including 6.381. Segment networks to limit the potential impact of exploitation for versions prior to and including 6.381.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-1358

Affected Products

Airleader Master