CVE-2020-37052

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) AirControl 1.4.2 contiene una vulnerabilidad de ejecución remota de código de pre-autenticación que permite a atacantes no autenticados ejecutar comandos de sistema arbitrarios mediante inyección maliciosa de expresiones Java. Los atacantes pueden explotar el endpoint /.seam creando una URL especialmente diseñada con expresiones Java incrustadas para ejecutar comandos con los privilegios de sistema de la aplicación.

30 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 23:16

Updated : 2026-06-17 03:16


NVD link : CVE-2020-37052

Mitre link : CVE-2020-37052

CVE.ORG link : CVE-2020-37052


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')