CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-12-12. EPSS: 27.1% chance of exploitation in the next 30 days.
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected products
- Sierra Wireless ALEOS: before 4.4.9 (fixed in 4.4.9); before 4.11.0 (fixed in 4.11.0); before 4.9.4 (fixed in 4.9.4)
Published 2019-05-06. Last modified 2026-06-17.