CVE-2020-26510: Airleader Master Control

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.

Affected products

  • Airleader Airleader Master Control: up to and including 6.21

Published 2020-11-16. Last modified 2026-06-17.