First published: Fri May 04 2018(Updated: )
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sierrawireless Aleos | <4.4.7 | |
Sierrawireless Es440 | ||
Sierrawireless Gx400 | ||
Sierrawireless Gx440 | ||
Sierrawireless Ls300 | ||
Sierrawireless Aleos | <4.9.3 | |
Sierrawireless Es450 | ||
Sierrawireless Gx450 | ||
Sierrawireless Mp70 | ||
Sierrawireless Mp70e | ||
Sierrawireless Rv50 | ||
Sierrawireless Rv50x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10251 is a vulnerability in Sierra Wireless AirLink routers that could allow an attacker to execute arbitrary code and gain full control of the affected device.
Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7, as well as GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 are affected by CVE-2018-10251.
CVE-2018-10251 has a severity rating of 9.8, which is considered critical.
The Common Weakness Enumeration (CWE) ID for CVE-2018-10251 is CWE-1188 and CWE-862.
Yes, a fix is available for CVE-2018-10251. Users should update their firmware to version 4.4.7 or later for affected GX400, GX440, ES440, and LS300 routers, and version 4.9.3 or later for affected GX450, ES450, RV50, RV50X, MP70, and MP70E routers.