Junglewise Threat Intelligence

CVE-2018-4063: Sierra Wireless ALEOS unrestricted file upload in upload.cgi

CVE-2018-4063 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-12-12

Executive brief

Sierra Wireless AirLink gateways, which are industrial routers used to provide cellular connectivity for critical infrastructure and remote sites, contain a security flaw in their management interface. An attacker with valid login credentials can upload malicious files to the device's web server, allowing them to take full control of the router. This could lead to unauthorized access to the internal network, data interception, or a complete shutdown of remote communications.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the upload.cgi functionality of the Sierra Wireless ALEOS operating system used in AirLink gateways. The flaw allows an authenticated attacker to send a specially crafted HTTP request to upload executable files to a directory accessible by the webserver. Once uploaded, these files can be executed with the privileges of the webserver, leading to full system compromise. This vulnerability has been observed being exploited in the wild. Patches are available in ALEOS versions 4.4.9, 4.9.4, and 4.11.0 depending on the specific hardware model (e.g., ES450, GX450, RV50).

Affected products

  • Sierra Wireless ALEOS up to (excluding) 4.4.9, 4.9.4, or 4.11.0 depending on hardware model

Timeline

  • 2018-07-48: other: Talos vulnerability report ID
  • 2019-05-02: advisory: CISA ICSA-19-122-03 published
  • 2025-12-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog