ZeroHour
Security Affairspublished ()ingested @securityaffairs

Other Sierra AirLink router models affected by critical flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4061
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
8.8
group max
19% PoC
  • sierrawireless airlink es450 firmware
CVE-2018-4063
Unrestricted File Upload Leading to Code Execution in Sierra Wireless AirLink ALEOS

CVE-2018-4063 is an unrestricted upload of a file with a dangerous type (CWE-434) in the web server of Sierra Wireless AirLink gateways running ALEOS, where a specially crafted HTTP request can upload an executable file that becomes routable and accessible through the webserver. The flaw is triggered by an authenticated HTTP request, so an attacker must first have valid credentials for the device's web interface. With that access, an attacker can place executable code on the gateway and run it through the webserver, effectively achieving authenticated remote code execution on a device that often sits at the network edge of critical operations. Any organization running AirLink ALEOS gateways is potentially affected, and CISA notes that the impacted product may be end-of-life or end-of-service, with the recommended action being to discontinue use where mitigations are not available. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-12-12, indicating known exploitation in the wild, with a high EPSS score (27.1%, 98th percentile), no public proof-of-concept, and unknown ransomware usage.

Do: Inventory all AirLink gateways running ALEOS and check their ALEOS firmware versions against Sierra Wireless/Semtech advisories, then upgrade to currently supported firmware or discontinue use of any device CISA notes as EoL/EoS. Restrict the gateway web management interface to trusted management networks, rotate device credentials since authentication is required for exploitation, and look for unexpected uploaded files on the device webserver. Federal agencies must apply this fix per BOD 22-01 guidance following the 2025-12-12 KEV addition.

8.827% KEV PoC ×3
  • Sierra Wireless AirLink ALEOS
largetens of thousands of exposed AirLink gateways, with the total deployed fleet plausibly in the hundreds of thousands
Full article419 words · extracted from securityaffairs.com · click to collapse

Sierra Wireless is warning its customers that additional AiraLink router models are affected by critical vulnerabilities previously disclosed.

At the end of April, experts at Cisco Talos group disclosed a dozen
of vulnerabilities
in Sierra Wireless AirLink gateways and routers, including several serious flaws.

Sierra Wireless AirLink gateways and routers are widely used in enterprise environments to connect industrial equipment, smart devices, sensors, point-of-sale (PoS) systems, and Industrial Control systems (ICSs).

Experts discovered three flaws classified as “critical” (CVSS score 9.9) that can be exploited by an attacker to make changes to any system settings and execute arbitrary commands and code. An authenticated attacker could exploit the flaw by sending specially crafted HTTP requests to the targeted device.

The company is now warning that some of the flaws affect other Sierra Wireless’ AirLink routers using the ALEOS software.

According to the advisory published by the ICS CERT, the company patched seven vulnerabilities, two of which rated as ‘critical’ and five as ‘medium-severity’ vulnerabilities.

“Successful exploitation of these vulnerabilities could allow attackers to remotely execute code, discover user credentials, upload files, or discover file paths,” reads the security advisory.

Below the list of affected Sierra AirLink models:

  • LS300, GX400, GX440, and ES440: Version 4.4.8 and prior
  • GX450 and ES450: All versions prior to 4.9.4
  • MP70, MP70E, RV50, RV50X, LX40, and LX60: All versions prior to 4.12

The most severe flaws disclosed by Sierra are an OS command-injection vulnerability tracked as CVE-2018-4061 (CVSS score 9.1) and an unrestricted file upload vulnerability tracked as CVE-2018-4063
(CVSS score 9.1).

The CVE-2018-4061 is classified as an improper neutralization of special elements used in an os command (‘os command injection’). The flaw could be exploited sending specially crafted authenticated HTTP request to the vulnerable devices resulting in remote code execution.

The CVE-2018-4063 vulnerability is classified as an unrestricted upload of file with dangerous type. The flaw could be exploited by sending a specially crafted authenticated HTTP request to upload a file, resulting in an executable, routable code upload to the web server.

Sierra also disclosed the following five medium-severity vulnerabilities:

Sierra Wireless has addressed the flaws with security fixes, users have to apply them as soon as possible.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Sierra Airlink, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/84972/hacking/sierra-wireless-airlink-flaws.html