CVE-2018-4063
9.5 CISA KEVSierra Wireless · AirLink ALEOS
An authenticated remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ALEOS firmware, allowing attackers to upload and execute arbitrary files.
Executive summary
This critical vulnerability in Sierra Wireless AirLink ALEOS firmware allows authenticated attackers to achieve remote code execution and is currently being exploited in the wild.
Vulnerability
This is a remote code execution vulnerability located in the upload.cgi functionality. An authenticated attacker can trigger this flaw by uploading a malicious file that overwrites existing executables, which then execute with root privileges due to a lack of proper file validation.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational infrastructure. Successful exploitation grants an attacker full control over the affected gateway, potentially leading to complete system compromise, unauthorized network access, and the deployment of malicious payloads such as botnets or cryptocurrency miners.
Remediation
Immediate Action: Update affected devices to firmware version 4.4.9 for LS300, GX400, GX440, and ES440; version 4.9.4 for GX450 and ES450; or version 4.12 for MP70, MP70E, RV50, RV50X, LX40, and LX60.
Proactive Monitoring: Monitor network logs for suspicious HTTP requests targeting the upload.cgi endpoint and investigate any unauthorized file modifications on the gateway filesystem.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only and ensure that all default credentials have been changed to strong, unique passwords.
Exploitation status
Public Exploit Available: Yes, public exploits are available as documented in technical research write-ups and security databases.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of the remote code execution impact, organizations must prioritize patching these gateways immediately. Failure to update vulnerable firmware leaves critical network infrastructure exposed to persistent and malicious control by unauthorized actors.
Sources
- packetstormsecurity.com
- ics-cert.us-cert.gov
- 108147 Vulnerability database entry
- talosintelligence.com