Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-15849 | An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 15 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sierrawireless airlink Es440
Sierrawireless airlink Gx400 Sierrawireless airlink Gx440 Sierrawireless airlink Gx450 Sierrawireless airlink Ls300 Sierrawireless airlink Lx40 Sierrawireless airlink Lx60 Sierrawireless airlink Mp70 Sierrawireless airlink Mp70e Sierrawireless airlink Rv50 Sierrawireless airlink Rv50x Sierrawireless aleos |
|
| CPEs | cpe:2.3:h:sierrawireless:airlink_es440:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_gx400:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_gx440:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_gx450:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_ls300:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_lx40:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_lx60:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_mp70:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_mp70e:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_rv50:-:*:*:*:*:*:*:* cpe:2.3:h:sierrawireless:airlink_rv50x:-:*:*:*:*:*:*:* cpe:2.3:o:sierrawireless:aleos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sierrawireless airlink Es450 Firmware
|
Sierrawireless airlink Es440
Sierrawireless airlink Gx400 Sierrawireless airlink Gx440 Sierrawireless airlink Gx450 Sierrawireless airlink Ls300 Sierrawireless airlink Lx40 Sierrawireless airlink Lx60 Sierrawireless airlink Mp70 Sierrawireless airlink Mp70e Sierrawireless airlink Rv50 Sierrawireless airlink Rv50x Sierrawireless aleos |
| Metrics |
cvssV3_0
|
Fri, 12 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Fri, 12 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Fri, 12 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-12-13T04:55:16.023Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-4063
Updated: 2024-08-05T05:04:29.488Z
Status : Analyzed
Published: 2019-05-06T19:29:00.637
Modified: 2025-12-15T15:18:49.987
Link: CVE-2018-4063
No data.
OpenCVE Enrichment
No data.
EUVD