PT-2019-10790 · Sierra Wireless · Sierra Wireless Airlink Es450

Carl Hurd

+1

·

Published

2019-05-06

·

Updated

2025-12-15

·

CVE-2018-4063

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sierra Wireless AirLink ES450 version 4.9.3 Sierra Wireless AirLink ALEOS (affected versions not specified)
Description A remote code execution issue exists in the upload.cgi functionality of Sierra Wireless AirLink devices. A crafted HTTP request can upload a file, leading to executable code being uploaded and accessible on the webserver. An authenticated attacker can trigger this issue. Recent attacks have leveraged this to deliver malware, including botnets and cryptocurrency miners. The vulnerability allows attackers to execute arbitrary code on affected routers, potentially leveraging administrative privileges. The vulnerability is actively exploited in the wild. The upload.cgi functionality is vulnerable to unrestricted file uploads.
Recommendations Sierra Wireless AirLink ES450 version 4.9.3: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Sierra Wireless AirLink ALEOS: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2018-4063

Affected Products

Sierra Wireless Airlink Es450