Ubiquiti, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with AirControl.
Products
Clear product- AirControl1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37052CRITICAL | AirControl 1.4.2 - PreAuth Remote Code ExecutionAirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges. CWE-94Jan 30, 2026 | CVSS9.3v4.0 | EPSS1.17% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |