ZeroHour

CVE-2018-4063

KEV PoC ×3large

Unrestricted File Upload Leading to Code Execution in Sierra Wireless AirLink ALEOS

CISA: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

CVSS 3.1
8.8 high
EPSS
27%p98
Published
()
KEV added
AI analysis

CVE-2018-4063 is an unrestricted upload of a file with a dangerous type (CWE-434) in the web server of Sierra Wireless AirLink gateways running ALEOS, where a specially crafted HTTP request can upload an executable file that becomes routable and accessible through the webserver. The flaw is triggered by an authenticated HTTP request, so an attacker must first have valid credentials for the device's web interface. With that access, an attacker can place executable code on the gateway and run it through the webserver, effectively achieving authenticated remote code execution on a device that often sits at the network edge of critical operations. Any organization running AirLink ALEOS gateways is potentially affected, and CISA notes that the impacted product may be end-of-life or end-of-service, with the recommended action being to discontinue use where mitigations are not available. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-12, indicating known exploitation in the wild, with a high EPSS score (27.1%, 98th percentile), no public proof-of-concept, and unknown ransomware usage.

What to do: Inventory all AirLink gateways running ALEOS and check their ALEOS firmware versions against Sierra Wireless/Semtech advisories, then upgrade to currently supported firmware or discontinue use of any device CISA notes as EoL/EoS. Restrict the gateway web management interface to trusted management networks, rotate device credentials since authentication is required for exploitation, and look for unexpected uploaded files on the device webserver. Federal agencies must apply this fix per BOD 22-01 guidance following the 2025-12-12 KEV addition.

Affected
Sierra Wireless AirLink ALEOS
Estimated exposure
largetens of thousands of exposed AirLink gateways, with the total deployed fleet plausibly in the hundreds of thousands — Sierra Wireless/Semtech AirLink cellular gateways running ALEOS are widely deployed for fleet, utility, industrial, and point-of-sale/ATM connectivity with a cumulative deployed base likely in the hundreds of thousands, while public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CISA Known Exploited Vulnerability
Affected
Sierra Wireless AirLink ALEOS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sierrawireless
Products
aleos
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news