CVE-2018-10251: Critical severity sierra wireless aleos vulnerability
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10251?
CVE-2018-10251 is a vulnerability in Sierra Wireless AirLink routers that could allow an attacker to execute arbitrary code and gain full control of the affected device.
Which Sierra Wireless AirLink routers are affected by CVE-2018-10251?
Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7, as well as GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 are affected by CVE-2018-10251.
How severe is CVE-2018-10251?
CVE-2018-10251 has a severity rating of 9.8, which is considered critical.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-10251?
The Common Weakness Enumeration (CWE) ID for CVE-2018-10251 is CWE-1188 and CWE-862.
Is there a fix available for CVE-2018-10251?
Yes, a fix is available for CVE-2018-10251. Users should update their firmware to version 4.4.7 or later for affected GX400, GX440, ES440, and LS300 routers, and version 4.9.3 or later for affected GX450, ES450, RV50, RV50X, MP70, and MP70E routers.