CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

Published May 6, 2019
·
Updated

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Other sources

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA

Affected Software

19 affected componentsFixes available
Sierrawireless Airlink Es450 Firmware=4.9.3
Sierrawireless Airlink Es450
Sierra Wireless AirLink ALEOS
Sierra Wireless LS300, GX400, GX440, and ES440<4.4.9
4.4.9
All of the following
Sierrawireless Aleos<4.4.9
Any of the following
Sierrawireless Airlink Es440
Sierrawireless Airlink Gx400
Sierrawireless Airlink Gx440
Sierrawireless Airlink Ls300
All of the following
Sierrawireless Aleos<4.11.0
Any of the following
Sierrawireless Airlink Lx40
Sierrawireless Airlink Lx60
Sierrawireless Airlink Mp70
Sierrawireless Airlink Mp70e
Sierrawireless Airlink Rv50
Sierrawireless Airlink Rv50x
All of the following
Sierrawireless Aleos<4.9.4
Any of the following
Sierrawireless Airlink Es450
Sierrawireless Airlink Gx450

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.4.9
  2. Upgrade

    Upgrade Sierra Wireless AirLink ALEOS to a version that resolves this vulnerability.

    Fixed in 4.4.9
  3. Compensating control

    Discontinue use of the product if mitigations are unavailable (Users should discontinue product utilization of Sierra Wireless AirLink ALEOS / AirLink ES450).

  4. Compensating control

    Follow applicable BOD 22-01 guidance for cloud services.

Event History

May 6, 2019
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Dec 12, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Data Sourced
via ICS·07:25 PM
SeverityWeaknessAffected Software
Oct 5, 58358
Event
via NVD·04:41 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-4063?

CVE-2018-4063 is an exploitable remote code execution vulnerability in the upload.cgi functionality of Sierra Wireless AirLink ES450 Firmware 4.9.3.

2

What is the severity of CVE-2018-4063?

The severity of CVE-2018-4063 is critical with a CVSS score of 8.8.

3

What is the affected software for CVE-2018-4063?

The affected software for CVE-2018-4063 is Sierra Wireless AirLink ES450 Firmware 4.9.3.

4

How does CVE-2018-4063 work?

CVE-2018-4063 can be exploited by using a specially crafted HTTP request to upload a file, resulting in executable code being uploaded to the webserver.

5

Are there any references for CVE-2018-4063?

Yes, here are some references for CVE-2018-4063: [1](http://packetstormsecurity.com/files/152648/Sierra-Wireless-AirLink-ES450-ACEManager-upload.cgi-Remote-Code-Execution.html), [2](http://www.securityfocus.com/bid/108147), [3](https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203