Skip to content
COOEY

EXPOSURES › CVE-2018-4063

CVE-2018-4063

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-4063 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Sierra Wireless AirLink ALEOS exposed unrestricted upload of executable files, leading to potential remote code execution.

Sierra Wireless AirLink ALEOS allowed unauthorized uploads of executable files, which could be exploited remotely to execute code, putting DIB systems at risk. Users were advised to stop using the product.

Shame score — Unrestricted upload of executable files leading to remote code execution, with the product being end-of-life and end-of-service.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.