← Back to browse · API

CVE-2018-4063

Severity
HIGH
CVSS
8.8
EPSS
0.27512
Risk score
69.83
CISA KEV
Yes
PoC
No
Published
2019-05-06
Modified
2026-05-22
First seen
2026-08-07
Aliases
EUVD-2018-15849, GHSA-96PR-35F4-CF4C
Products
Sierra Wireless:AirLink ALEOS, n/a:Sierra Wireless Sierra Wireless AirLink ES450 FW 4.9.3
Sources
cisa.gov CVE-2018-4063
euvd EUVD-2018-15849

Description

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

References