InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks
Technology

CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks

December 13, 2025 4 Min Read
Share

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild.

CVE-2018-4063 (CVSS score: 8.8/9.9) refers to an unrestricted file upload vulnerability that can be exploited to cause remote code execution via a malicious HTTP request.

“A specially crafted HTTP request could result in a file being uploaded, which could result in executable code being uploaded and routed to a web server,” the agency said. “An attacker could craft an authenticated HTTP request to trigger this vulnerability.”

Details of the six-year-old vulnerability were published by Cisco Talos in April 2019 and described as an exploitable remote code execution vulnerability in the ACEManager “upload.cgi” function of Sierra Wireless AirLink ES450 firmware version 4.9.3. Talos reported this flaw to the Canadian company in December 2018.

The company says, “This vulnerability exists in the template file upload function within AirLink 450.” When you upload a template file, you can specify the name of the file you are uploading.

“There are no restrictions protecting files that are currently on the device and used for normal operations. If a file is uploaded with the same name as a file that already exists in the directory, it will inherit the permissions of that file.”

Talos noted that some files present within the directory (such as “fw_upload_init.cgi” and “fw_status.cgi”) have executable permissions on the device. This means that an attacker can send an HTTP request to the “/cgi-bin/upload.cgi” endpoint to upload a file with the same name and execute code.

See also  $50 batter ram attack breaks Intel and AMD cloud security protections

This is further exacerbated by the fact that ACEManager runs as root, which means that any shell scripts or executables uploaded to the device will also run with elevated privileges.

The addition of CVE-2018-4063 to the KEV catalog comes a day after Forescout’s 90-day honeypot analysis revealed that industrial routers are the most attacked devices in operational technology (OT) environments, with attackers exploiting the following flaws to distribute botnets and crypto miner malware families such as RondoDox, Redtail, and ShadowV2.

We have also recorded an attack from a previously undocumented threat cluster named Chaya_005 that weaponized CVE-2018-4063 and uploaded an unspecified malicious payload named ‘fw_upload_init.cgi’ in early January 2024. No successful exploits have been detected since then.

Forescout Research – Vedere Labs said, “Chaya_005 appears to be a broader reconnaissance operation testing vulnerabilities from multiple vendors rather than focusing on a single vulnerability,” adding that the cluster is likely no longer a “significant threat.”

In view of the active exploitation of CVE-2018-4063, Federal Civilian Executive Branch (FCEB) agencies recommend that you update your devices to a supported version or discontinue use of the product by January 2, 2026, as it has reached End of Life status.

Share This Article
Twitter Copy Link
Previous Article This can't-miss bundle offers 88% off Doom Eternal and other must-have FPS games This can’t-miss bundle offers 88% off Doom Eternal and other must-have FPS games
Next Article Former Trump Justice Department lawyer says 'corrupt' University of California anti-Semitism investigation led to resignation Former Trump Justice Department lawyer says ‘corrupt’ University of California anti-Semitism investigation led to resignation

You Might Also Like

DeskRAT Malware Campaign
Technology

APT36 targets Indian government with Golang-based DeskRAT malware campaign

8 Min Read
UNC1549 Hacking 34 devices from 11 telecom companies via LinkedIn Job Lures and Minibike malware
Technology

UNC1549 Hacking 34 devices from 11 telecom companies via LinkedIn Job Lures and Minibike malware

8 Min Read
Five people plead guilty in US for helping North Korean IT workers infiltrate 136 companies
Technology

Five people plead guilty in US for helping North Korean IT workers infiltrate 136 companies

7 Min Read
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
Technology

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?