PT-2018-5753 · Sierra Wireless · Sierra Wireless Airlink Rv50+5

Published

2018-05-04

·

Updated

2018-06-13

·

CVE-2017-15043

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers versions prior to 4.4.5 Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers versions prior to 4.9
Description: The issue is caused by insufficient input validation on user-controlled input in an HTTP request to the targeted device. An authenticated remote attacker could exploit this by sending a crafted HTTP request to gain full control of an affected system, including issuing commands with root privileges.
Recommendations: For Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5, update to firmware version 4.4.5 or later. For Sierra Wireless AirLink GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9, update to firmware version 4.9 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15043

Affected Products

Sierra Wireless Airlink Es440
Sierra Wireless Airlink Es450
Sierra Wireless Airlink Gx400
Sierra Wireless Airlink Ls300
Sierra Wireless Airlink Mp70
Sierra Wireless Airlink Rv50