AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-30 23:16
Updated : 2026-02-03 16:44
NVD link : CVE-2020-37052
Mitre link : CVE-2020-37052
CVE.ORG link : CVE-2020-37052
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
