CVE-2018-4063
HIGH KEVSierrawireless Aleos < 4.4.9 - Unrestricted File Upload
Title source: ruleDescription
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
References (6)
Scores
CVSS v3
8.8
EPSS
0.0080
EPSS Percentile
74.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-12-12
VulnCheck KEV
2025-12-11
ENISA EUVD
EUVD-2018-15849
CWE
CWE-434
Status
published
Products (1)
sierrawireless/aleos
< 4.4.9
Published
May 06, 2019
KEV Added
Dec 12, 2025
Tracked Since
Feb 18, 2026