Vulnerability record · CVE-2018-4063 · published 6 May 2019
CVE-2018-4063: Sierra Wireless ALEOS upload.cgi unrestricted file upload RCE
Sierrawireless · Aleos
Sierra Wireless AirLink ES450 running ALEOS 4.9.3 exposes an unrestricted file upload in upload.cgi. A crafted HTTP request can upload executable code that is then routable to the webserver, giving remote code execution. The flaw requires authentication but no user interaction, and the product is now on CISA's Known Exploited Vulnerabilities catalog.
Description
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated code execution on an internet-facing cellular router with public exploit code and KEV listing, though it requires valid credentials.
What it is
Sierra Wireless AirLink ES450 running ALEOS 4.9.3 exposes an unrestricted file upload in upload.cgi. A crafted HTTP request can upload executable code that is then routable to the webserver, giving remote code execution. The flaw requires authentication but no user interaction, and the product is now on CISA's Known Exploited Vulnerabilities catalog.
Impact
An authenticated attacker gains remote code execution on the device, with high impact to confidentiality, integrity and availability. That level of control over a cellular router can expose or disrupt the network it connects.
Attack surface
Reached over the network via HTTP requests to the upload.cgi endpoint; the CVSS vector (AV:N/PR:L/UI:N) indicates low-privileged authentication is required and no user interaction. No other reachability detail is given in the record.
Exploitation
CISA added this to the KEV catalog on 2025-12-12 with a remediation due date of 2026-01-02, and EPSS gives a 30-day probability of 0.27059 (97.9th percentile). Multiple references are tagged Exploit, including Talos and Packet Storm, so public exploit material exists; no ransomware campaign use is documented.
What to do
- Apply the vendor mitigation or fixed firmware per Sierra Wireless instructions, or discontinue use of the affected product if no fix is available, as directed by CISA KEV.
- Restrict management and upload.cgi access to trusted networks and disable remote administration where not required.
- Enforce strong unique credentials and least privilege on device accounts to limit the low-privileged access the exploit needs.
- Monitor or block unexpected file uploads to the device webserver and alert on new executable files appearing in web-served paths.
Detection
- Inspect HTTP logs for POST requests to upload.cgi, especially with executable or script file types.
- Alert on new or modified files in webserver-served directories on AirLink ES450 devices.
- Monitor for unexpected outbound connections or processes spawned on the router after upload activity.
- Correlate device management logins with subsequent upload requests to catch authenticated abuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-4063 to the Known Exploited Vulnerabilities catalog on 12 December 2025 as "Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 January 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-4063 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.