CVE-2018-4063Active Exploitation(sierrawireless / airlink_es440)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for sierrawireless airlink_es440 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-02. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airlink_es440
  • airlink_es450
  • airlink_gx400
  • airlink_gx440

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
airlink_es440airlink_es450airlink_gx400airlink_gx440airlink_gx450airlink_ls300airlink_lx40airlink_lx60airlink_mp70airlink_mp70e

1 version affected across 13 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-23: 1Active Exploitation · 2026-04-23: 104-23
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestrict @CISACyber https://www.rfr.bz/tac6750

    Post summary

    The tweet announces that CVE‑2018‑4063 has entered CISA’s Known Exploited Vulnerabilities catalog due to documented active exploitation, with no PoC, patch, or technical details disclosed.

    0001042
    1.5K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
HWsierrawirelessairlink_es440---
HWsierrawirelessairlink_es450---
HWsierrawirelessairlink_gx400---
HWsierrawirelessairlink_gx440---
HWsierrawirelessairlink_gx450---
HWsierrawirelessairlink_ls300---
HWsierrawirelessairlink_lx40---
HWsierrawirelessairlink_lx60---
HWsierrawirelessairlink_mp70---
HWsierrawirelessairlink_mp70e---
HWsierrawirelessairlink_rv50---
HWsierrawirelessairlink_rv50x---
OSsierrawirelessaleos---

Explore more