


Perceptive Security
SOC/SIEM Consultancy

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, res…
Published:
12 december 2025 om 00:00:00
Alert date:
12 december 2025 om 19:01:25
Source:
cisa.gov
Sierra Wireless AirLink ALEOS contains an unrestricted upload vulnerability allowing attackers to upload executable files via specially crafted HTTP requests. The vulnerability requires authentication but can result in code execution on the webserver. The affected product may be end-of-life or end-of-service, and users are advised to discontinue use. This is a critical vulnerability that allows remote code execution through file upload functionality.
Technical details
Mitigation steps:
Affected products:
Sierra Wireless AirLink ALEOS
Related links:
https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/sierra-wireless-technical-bulletin---swi-psa-2019-003
https://www.cisa.gov/news-events/ics-advisories/icsa-19-122-03
https://source.sierrawireless.com/resources/airlink/hardware_reference_docs/airlink_es450_eol
https://nvd.nist.gov/vuln/detail/CVE-2018-4063
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
