PT-2019-10790 · Sierra Wireless · Sierra Wireless Airlink Es450
Carl Hurd
+1
·
Published
2019-05-06
·
Updated
2025-12-15
·
CVE-2018-4063
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sierra Wireless AirLink ES450 version 4.9.3
Sierra Wireless AirLink ALEOS (affected versions not specified)
Description
A remote code execution issue exists in the upload.cgi functionality of Sierra Wireless AirLink devices. A crafted HTTP request can upload a file, leading to executable code being uploaded and accessible on the webserver. An authenticated attacker can trigger this issue. Recent attacks have leveraged this to deliver malware, including botnets and cryptocurrency miners. The vulnerability allows attackers to execute arbitrary code on affected routers, potentially leveraging administrative privileges. The vulnerability is actively exploited in the wild. The
upload.cgi functionality is vulnerable to unrestricted file uploads.Recommendations
Sierra Wireless AirLink ES450 version 4.9.3: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Sierra Wireless AirLink ALEOS: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sierra Wireless Airlink Es450