CVE-2018-4063

HIGH KEV

Sierrawireless Aleos < 4.4.9 - Unrestricted File Upload

Title source: rule

Description

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Scores

CVSS v3 8.8
EPSS 0.0080
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-12-12
VulnCheck KEV 2025-12-11
ENISA EUVD EUVD-2018-15849
CWE
CWE-434
Status published
Products (1)
sierrawireless/aleos < 4.4.9
Published May 06, 2019
KEV Added Dec 12, 2025
Tracked Since Feb 18, 2026