CVE-2025-46612 Details
Description
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.
A critical vulnerability exists in the Panel Designer dashboard of Airleader Master and Airleader Easy versions prior to 6.36. This issue allows remote attackers to execute arbitrary commands on the underlying operating system by exploiting an unrestricted file upload feature. To successfully exploit this vulnerability, an attacker must log into the administrator console using default credentials, which are weak and easily guessable, and upload a JSP file that serves as a web shell.
Users are advised to update to Airleader Master or Airleader Easy version 6.36 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-036.txt | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| airleader easy firmware | < 6.36 |
CPE
Remediation
| |
| airleader easy | All versions |
CPE
Remediation
| |
| airleader master ii+ firmware | < 6.36 |
CPE
Remediation
| |
| airleader master ii+ | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | Initial Analysis | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |
| Jun 10, 2025 | CVE Modified | CISA-ADP |