CVE-2025-46612: Airleader Easy Firmware
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.
Affected products
- Airleader Easy Firmware: before 6.36 (fixed in 6.36)
- Airleader Master Ii+ Firmware: before 6.36 (fixed in 6.36)
Published 2025-06-10. Last modified 2026-06-17.