← Browse

CVE-2018-4063

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
27.1%
98.0th percentile
CISA KEV
Listed
Added 2025-12-12 · patch by 2026-01-02
Weakness / dates
Published — · modified —

Timeline

Description

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Official: NVD · CVE.org