CVE-2018-4061: Command Injection
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-4061?
CVE-2018-4061 is a command injection vulnerability that exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 firmware version 4.9.3.
How severe is CVE-2018-4061?
CVE-2018-4061 has a severity rating of 8.8, which is classified as critical.
What is the affected software for CVE-2018-4061?
The affected software for CVE-2018-4061 is Sierra Wireless AirLink ES450 firmware version 4.9.3.
How can the command injection vulnerability be exploited?
The command injection vulnerability in CVE-2018-4061 can be exploited by sending a specially crafted HTTP request that injects arbitrary commands, resulting in arbitrary command execution.
Are there any known references for CVE-2018-4061?
Yes, there are several references available for CVE-2018-4061, including a link to a security advisory and a security focus article.