Products: 7
Vulnerabilities: 4
Known Exploited: 0
2
Critical Level Threats
2
High Level Threats
0
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-1358
Airleader Master Unrestricted Upload of File with Dangerous Type
Last Modified: Apr 16, 2026
Published: Feb 12, 2026
CVE-2025-46612
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.
Last Modified: Oct 16, 2025
Published: Jun 10, 2025
CVE-2020-26510
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
Last Modified: Nov 21, 2024
Published: Nov 16, 2020
CVE-2020-26509
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
Last Modified: Nov 21, 2024
Published: Nov 16, 2020
Items Per Page
