← Vulnerability feed

Vulnerability record · CVE-2018-4070 · published 6 May 2019

CVE-2018-4070: Sierrawireless airlink es450 firmware information exposure vulnerability

Sierrawireless · Airlink Es450 Firmware

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Get_Task.cgi endpoint.

8.8 CVSS 3.0 High EPSS 18% · top 2.9% CWE-200 · Information exposure
8.8CVSS 3.0 base score, v2 4.0
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not have any restricted configuration settings, so once the MSCIID is discovered, any authenticated user can send configuration changes using the /cgi-bin/Embedded_Ace_Get_Task.cgi endpoint.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-4070 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-4072Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4073Sierrawireless airlink es450 firmware incorrect permission assignment vulnerabilityAn exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW…EPSS 26%8.8CVE-2018-4066Sierrawireless airlink es450 firmware cross-site request forgery vulnerabilityAn exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially…EPSS 1.9%8.8CVE-2018-4071Sierrawireless airlink es450 firmware information exposure vulnerabilityAn exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 F…EPSS 18%8.8CVE-2018-4061Sierrawireless airlink es450 firmware os command injection vulnerabilityAn exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A spec…EPSS 19%8.1CVE-2018-4062Sierrawireless airlink es450 firmware hard-coded credentials vulnerabilityA hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the We…EPSS 5.3%7.5CVE-2018-4069Sierrawireless airlink es450 firmware information exposure vulnerabilityAn information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManag…EPSS 4.1%7.1CVE-2018-4064Sierrawireless airlink es450 firmware improper authentication vulnerabilityAn exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. …EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2018-4070), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.