← Vulnerability feed

Vulnerability record · CVE-2018-4062 · published 6 May 2019

CVE-2018-4062: Sierrawireless airlink es450 firmware hard-coded credentials vulnerability

Sierrawireless · Airlink Es450 Firmware

A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.

8.1 CVSS 3.0 High EPSS 5.3% · top 7.7% CWE-798 · Hard-coded credentials
8.1CVSS 3.0 base score, v2 9.3
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4062 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-4072Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4073Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4066Sierrawireless airlink es450 firmware cross-site request forgery vulnerabilityAn exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…EPSS 1.9%8.8CVE-2018-4070Sierrawireless airlink es450 firmware information exposure vulnerabilityAn exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…EPSS 18%8.8CVE-2018-4071Sierrawireless airlink es450 firmware information exposure vulnerabilityAn exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…EPSS 18%8.8CVE-2018-4061Sierrawireless airlink es450 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A spec…EPSS 19%7.5CVE-2018-4069Sierrawireless airlink es450 firmware information exposure vulnerabilityAn information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManag…EPSS 4.1%7.1CVE-2018-4064Sierrawireless airlink es450 firmware improper authentication vulnerabilityAn exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. …EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2018-4062), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.