ZeroHour

Vulnerabilities

52 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38321
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, d

OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.

NVD description · AI analysis pending
7.51%
  • sierrawireless aleos
CVE-2023-40459
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Den

The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

NVD description · AI analysis pending
7.5
group max
2%
  • sierrawireless aleos
CVE-2023-40458
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.

NVD description · AI analysis pending
7.5<1%
  • sierrawireless aleos
CVE-2022-46649
+1 in the same advisory: …46650
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the d

Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.

NVD description · AI analysis pending
8.8
group max
2% PoC
  • sierrawireless aleos
CVE-2019-11851
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to e

The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.

NVD description · AI analysis pending
9.82%
  • sierrawireless aleos
CVE-2019-13988
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).

Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).

NVD description · AI analysis pending
6.5<1%
  • sierrawireless mgos
CVE-2020-11101
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrato

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

NVD description · AI analysis pending
9.8<1%
  • sierrawireless airlink mobility manager
CVE-2020-8782
+1 in the same advisory: …8781
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

NVD description · AI analysis pending
9.8
group max
2%
  • sierrawireless aleos
CVE-2019-11855
An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

NVD description · AI analysis pending
9.8
group max
1%
  • sierrawireless aleos
CVE-2020-8948
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary fold

The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.

NVD description · AI analysis pending
7.8<1%
  • sierrawireless mobile broadband driver package
CVE-2018-4064
An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
7.114% PoC
  • sierrawireless airlink es450 firmware
CVE-2018-4072
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task.cgi executable is used to change MSCII configuration values within the configuration manager of the AirLink ES450. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Set_Task.cgi endpoint.

NVD description · AI analysis pending
8.8
group max
26% PoC
  • sierrawireless airlink es450 firmware
CVE-2018-4063
Unrestricted File Upload Leading to Code Execution in Sierra Wireless AirLink ALEOS

CVE-2018-4063 is an unrestricted upload of a file with a dangerous type (CWE-434) in the web server of Sierra Wireless AirLink gateways running ALEOS, where a specially crafted HTTP request can upload an executable file that becomes routable and accessible through the webserver. The flaw is triggered by an authenticated HTTP request, so an attacker must first have valid credentials for the device's web interface. With that access, an attacker can place executable code on the gateway and run it through the webserver, effectively achieving authenticated remote code execution on a device that often sits at the network edge of critical operations. Any organization running AirLink ALEOS gateways is potentially affected, and CISA notes that the impacted product may be end-of-life or end-of-service, with the recommended action being to discontinue use where mitigations are not available. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-12, indicating known exploitation in the wild, with a high EPSS score (27.1%, 98th percentile), no public proof-of-concept, and unknown ransomware usage.

Do: Inventory all AirLink gateways running ALEOS and check their ALEOS firmware versions against Sierra Wireless/Semtech advisories, then upgrade to currently supported firmware or discontinue use of any device CISA notes as EoL/EoS. Restrict the gateway web management interface to trusted management networks, rotate device credentials since authentication is required for exploitation, and look for unexpected uploaded files on the device webserver. Federal agencies must apply this fix per BOD 22-01 guidance following the 2025-12-12 KEV addition.

8.827% KEV PoC ×3
  • Sierra Wireless AirLink ALEOS
largetens of thousands of exposed AirLink gateways, with the total deployed fleet plausibly in the hundreds of thousands
CVE-2018-10251
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E rout

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.

NVD description · AI analysis pending
9.84%
  • sierrawireless aleos
CVE-2017-15043
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E rout

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system.

NVD description · AI analysis pending
8.84%
  • sierrawireless gx440 firmware
  • sierrawireless es440 firmware
  • sierrawireless ls300 firmware
  • +1 more
CVE-2017-9247
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to laun

Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges.

NVD description · AI analysis pending
7.8<1%
  • sierrawireless sierra wireless em7345 software
  • sierrawireless sierra wireless em7455 software
  • sierrawireless sierra wireless location sensor driver
CVE-2016-5068
+4 in the same advisory: …5069 …5070 …5067 …5071
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • sierrawireless aleos firmware