← Vulnerability feed

Vulnerability record · CVE-2018-4063 · published 6 May 2019

CVE-2018-4063: Sierra Wireless ALEOS upload.cgi unrestricted file upload RCE

Sierrawireless · Aleos

Sierra Wireless AirLink ES450 running ALEOS 4.9.3 exposes an unrestricted file upload in upload.cgi. A crafted HTTP request can upload executable code that is then routable to the webserver, giving remote code execution. The flaw requires authentication but no user interaction, and the product is now on CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 12 Dec 2025 EPSS 27% · top 2.0% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.0
27%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References, 5 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityRemote authenticated code execution on an internet-facing cellular router with public exploit code and KEV listing, though it requires valid credentials.

What it is

Sierra Wireless AirLink ES450 running ALEOS 4.9.3 exposes an unrestricted file upload in upload.cgi. A crafted HTTP request can upload executable code that is then routable to the webserver, giving remote code execution. The flaw requires authentication but no user interaction, and the product is now on CISA's Known Exploited Vulnerabilities catalog.

Impact

An authenticated attacker gains remote code execution on the device, with high impact to confidentiality, integrity and availability. That level of control over a cellular router can expose or disrupt the network it connects.

Attack surface

Reached over the network via HTTP requests to the upload.cgi endpoint; the CVSS vector (AV:N/PR:L/UI:N) indicates low-privileged authentication is required and no user interaction. No other reachability detail is given in the record.

Exploitation

CISA added this to the KEV catalog on 2025-12-12 with a remediation due date of 2026-01-02, and EPSS gives a 30-day probability of 0.27059 (97.9th percentile). Multiple references are tagged Exploit, including Talos and Packet Storm, so public exploit material exists; no ransomware campaign use is documented.

What to do

  • Apply the vendor mitigation or fixed firmware per Sierra Wireless instructions, or discontinue use of the affected product if no fix is available, as directed by CISA KEV.
  • Restrict management and upload.cgi access to trusted networks and disable remote administration where not required.
  • Enforce strong unique credentials and least privilege on device accounts to limit the low-privileged access the exploit needs.
  • Monitor or block unexpected file uploads to the device webserver and alert on new executable files appearing in web-served paths.

Detection

  • Inspect HTTP logs for POST requests to upload.cgi, especially with executable or script file types.
  • Alert on new or modified files in webserver-served directories on AirLink ES450 devices.
  • Monitor for unexpected outbound connections or processes spawned on the router after upload activity.
  • Correlate device management logins with subsequent upload requests to catch authenticated abuse.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-4063 to the Known Exploited Vulnerabilities catalog on 12 December 2025 as "Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 January 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4063 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-2897Sierrawireless aleos information exposure vulnerabilitySierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtai…EPSS 2.3%9.8CVE-2019-11851Sierrawireless aleos classic buffer overflow vulnerabilityThe ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote att…EPSS 1.6%9.8CVE-2020-8782Sierrawireless aleos vulnerabilityUnauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.EPSS 1.8%9.8CVE-2019-11855Sierrawireless aleos vulnerabilityAn RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.EPSS 1.2%9.8CVE-2018-10251Sierrawireless aleos missing authorization vulnerabilityA vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and…EPSS 4.5%9.1CVE-2019-11852Sierrawireless aleos out-of-bounds read vulnerabilityAn out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed v…EPSS 0.94%8.8CVE-2022-46649Sierrawireless aleos os command injection vulnerabilityAcemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell comman…EPSS 2.3%8.8CVE-2019-11859Sierrawireless aleos classic buffer overflow vulnerabilityA buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2018-4063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.