Airleader Master <= 6.21 devices have default credentials...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Nov 16, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
References