
[CVE-2020-37052: CRITICAL] AirControl 1.4.2 has a pre-auth remote code execution flaw letting attackers execute commands by injecting malicious Java expressions via crafted URLs at the /.seam endpoint.#cve,CVE-2020-37052,#cybersecurity https://cvefind.com/CVE-2020-37052
Post summary
The text announces a critical remote code execution vulnerability in AirControl 1.4.2 that permits pre‑authentication commands through crafted URLs at the /.seam endpoint, with no patch, exploit code, or evidence of active exploitation referenced.


