The ACEManager component of ALEOS 4.16 and earlier does not
validate uploaded file names and types, which could potentially allow
an authenticated user to perform client-side script execution within
ACEManager, altering the device functionality until the device is
restarted.
The ACEManager component of ALEOS 4.16 and earlier allows an
authenticated user with Administrator privileges to access a file
upload field which does not fully validate the file name, creating a
Stored Cross-Site Scripting condition.
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate and private key. An attacker with access to these items
could potentially perform a man in the middle attack between the
ACEManager client and ACEManager server.
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system.
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /openndsauth/ that lacks a custom query string parameter and client-token.