Vulnerabilities
52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-38321 | OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, d OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2023-40459 | The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Den The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. NVD description · AI analysis pending | 7.5 group max | 2% |
| — | ||
| CVE-2023-40458 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2022-46649 +1 in the same advisory: …46650 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the d Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device. NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2019-11851 | The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to e The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-13988 | Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing). Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing). NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2020-11101 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrato Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2020-8782 +1 in the same advisory: …8781 | Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2019-11855 | An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9. An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2020-8948 | The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary fold The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2018-4064 | An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 7.1 | 14% | PoC |
| — | |
| CVE-2018-4072 | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within the configuration manager of the AirLink ES450. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Set_Task.cgi endpoint. NVD description · AI analysis pending | 8.8 group max | 26% | PoC |
| — | |
| CVE-2018-4063 | Unrestricted File Upload Leading to Code Execution in Sierra Wireless AirLink ALEOS CVE-2018-4063 is an unrestricted upload of a file with a dangerous type (CWE-434) in the web server of Sierra Wireless AirLink gateways running ALEOS, where a specially crafted HTTP request can upload an executable file that becomes routable and accessible through the webserver. The flaw is triggered by an authenticated HTTP request, so an attacker must first have valid credentials for the device's web interface. With that access, an attacker can place executable code on the gateway and run it through the webserver, effectively achieving authenticated remote code execution on a device that often sits at the network edge of critical operations. Any organization running AirLink ALEOS gateways is potentially affected, and CISA notes that the impacted product may be end-of-life or end-of-service, with the recommended action being to discontinue use where mitigations are not available. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-12, indicating known exploitation in the wild, with a high EPSS score (27.1%, 98th percentile), no public proof-of-concept, and unknown ransomware usage. Do: Inventory all AirLink gateways running ALEOS and check their ALEOS firmware versions against Sierra Wireless/Semtech advisories, then upgrade to currently supported firmware or discontinue use of any device CISA notes as EoL/EoS. Restrict the gateway web management interface to trusted management networks, rotate device credentials since authentication is required for exploitation, and look for unexpected uploaded files on the device webserver. Federal agencies must apply this fix per BOD 22-01 guidance following the 2025-12-12 KEV addition. | 8.8 | 27% | KEV PoC ×3 |
| largetens of thousands of exposed AirLink gateways, with the total deployed fleet plausibly in the hundreds of thousands | |
| CVE-2018-10251 | A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E rout A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2017-15043 | A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E rout A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2017-9247 | Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to laun Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2016-5068 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — |