CVE-2020-26510: Airleader Master Control
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
Affected products
- Airleader Airleader Master Control: up to and including 6.21
Published 2020-11-16. Last modified 2026-06-17.