← Vulnerability feed

Vulnerability record · CVE-2018-4068 · published 6 May 2019

CVE-2018-4068: Sierrawireless airlink es450 firmware information exposure vulnerability

Sierrawireless · Airlink Es450 Firmware

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.

5.3 CVSS 3.0 Medium EPSS 11% · top 4.1% CWE-200 · Information exposure
5.3CVSS 3.0 base score, v2 5.0
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A HTTP request can result in disclosure of the default configuration for the device. An attacker can send an unauthenticated HTTP request to trigger this vulnerability.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4068 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-4072Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4073Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4066Sierrawireless airlink es450 firmware cross-site request forgery vulnerabilityAn exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…EPSS 1.9%8.8CVE-2018-4070Sierrawireless airlink es450 firmware information exposure vulnerabilityAn exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…EPSS 18%8.8CVE-2018-4071Sierrawireless airlink es450 firmware information exposure vulnerabilityAn exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…EPSS 18%8.8CVE-2018-4061Sierrawireless airlink es450 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A spec…EPSS 19%8.1CVE-2018-4062Sierrawireless airlink es450 firmware hard-coded credentials vulnerabilityA hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the We…EPSS 5.3%7.5CVE-2018-4069Sierrawireless airlink es450 firmware information exposure vulnerabilityAn information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManag…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2018-4068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.