CVE-2025-46612
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.
Published:Jun 10, 2025
Last Modified:Oct 16, 2025
EPS:Jun 10, 2025
EPSS Score:0.00189
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Airleader
Product
Easy
Airleader
Easy
Vendor
Airleader
Product
Easy Firmware
Airleader
Easy Firmware
Vendor
Airleader
Product
Master Ii\+
Airleader
Master Ii\+
Vendor
Airleader
Product
Master Ii\+ Firmware
Airleader
Master Ii\+ Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
