CVE-2020-37052
CRITICALAirControl 1.4.2 - RCE
Title source: llmDescription
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0019
EPSS Percentile
41.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
Ubiquiti, Inc./AirControl
<= 1.4.2
Published
Jan 30, 2026
Tracked Since
Feb 18, 2026