CVE-2015-2897: Sierra Wireless ALEOS

High severity, CVSS 10.0. EPSS: 2.3% chance of exploitation in the next 30 days.

Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.

Affected products

Published 2015-08-08. Last modified 2026-06-17.