PT-2018-5753 · Sierra Wireless · Sierra Wireless Airlink Rv50+5
Published
2018-05-04
·
Updated
2018-06-13
·
CVE-2017-15043
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers versions prior to 4.4.5
Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers versions prior to 4.9
Description:
The issue is caused by insufficient input validation on user-controlled input in an HTTP request to the targeted device. An authenticated remote attacker could exploit this by sending a crafted HTTP request to gain full control of an affected system, including issuing commands with root privileges.
Recommendations:
For Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5, update to firmware version 4.4.5 or later.
For Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9, update to firmware version 4.9 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sierra Wireless Airlink Es440
Sierra Wireless Airlink Es450
Sierra Wireless Airlink Gx400
Sierra Wireless Airlink Ls300
Sierra Wireless Airlink Mp70
Sierra Wireless Airlink Rv50