Description
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Credits
0xd0ff9 vs j3ssie
References
www.exploit-db.com/exploits/48541 (ExploitDB-48541)
www.ui.com/ (Vendor Homepage)
www.vulncheck.com/...ircontrol-preauth-remote-code-execution (VulnCheck Advisory: AirControl 1.4.2 - PreAuth Remote Code Execution)