CISA Flags High-Severity Flaw in Sierra Wireless ALEOS Routers

CISA Adds Critical Remote Code Execution Vulnerability CVE-2018-4063 in Sierra Wireless AirLink ALEOS Routers Due to Active Exploitation

  • CISA added a high-severity vulnerability in Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities catalog due to active exploitation.
  • CVE-2018-4063 allows remote code execution via an unrestricted file upload vulnerability in the router’s ACEManager “upload.cgi” function.
  • Exploitation involves sending authenticated HTTP requests to upload executable files with root privileges.
  • Forescout analysis confirmed industrial routers as heavily targeted, with active attacks by the threat group Chaya_005 using this vulnerability.
  • Federal agencies are urged to update or discontinue affected devices by January 2, 2026, as support has ended.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on December 12, 2025, added a critical vulnerability affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog. The decision follows confirmed reports of active exploitation of CVE-2018-4063, a flaw enabling remote code execution through an unrestricted file upload mechanism.

- Advertisement -

CVE-2018-4063, with a CVSS score between 8.8 and 9.9, resides in the ACEManager “upload.cgi” component of the AirLink ES450 firmware version 4.9.3. The vulnerability permits an attacker to send a specially crafted authenticated HTTP request to upload executable code to the router’s webserver. This occurs because uploaded files can overwrite existing ones without restrictions, inheriting executable permissions. Given that ACEManager runs with root privileges, uploaded scripts execute with elevated access, increasing the risk severity.

The vulnerability was first disclosed publicly by Cisco Talos in April 2019, after reporting it to Sierra Wireless in December 2018. Talos noted that critical files such as “fw_upload_init.cgi” can be replaced via this flaw, leading to full control over the device.

A recent 90-day honeypot study by Forescout identified industrial routers as prime targets in operational technology environments. Attackers often attempt to deploy Malware, including botnets and cryptocurrency miners like RondoDox, Redtail, and ShadowV2, by exploiting vulnerabilities including CVE-2018-4063. Notably, a previously unknown threat cluster named Chaya_005 weaponized this flaw in January 2024 to upload malicious payloads named “fw_upload_init.cgi.” Since then, no further successful exploitations have been observed, with Forescout deeming Chaya_005 not a “significant threat” anymore.

Due to ongoing exploitation risks and the product reaching end-of-support status, Federal Civilian Executive Branch (FCEB) agencies are advised to upgrade affected devices to a supported firmware version or discontinue their use by January 2, 2026, according to CISA’s advisory available here.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitfinex Hacker Ilya Lichtenstein Freed Early via First Step

Ilya Lichtenstein was released from prison after serving 14 months of a five-year sentence...

Waymo’s 2026 Expansion Could Drive Big Gains for GOOGL Surge

Alphabet rallied more than 60% in 2025 and enters 2026 with investor optimism tied...

Tesla shares slip as Q4 deliveries deemed largely neutral US

Tesla delivered 418,227 vehicles in Q4, slightly below the 422,850 company-polled consensus and last...

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...

EU Debates Digital Euro Privacy, Holding Limits: Compromises

The EU Council has endorsed the European Central Bank design for a digital euro...
- Advertisement -

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
Bitcoin (BTC) $ 89,989.00 2.05%
Ethereum (ETH) $ 3,124.47 4.59%
XRP (XRP) $ 1.99 6.57%
Bittensor (TAO) $ 246.06 8.34%
Polkadot (DOT) $ 2.10 5.72%
Cardano (ADA) $ 0.388157 9.96%
Chainlink (LINK) $ 13.28 6.71%
Hyperliquid (HYPE) $ 24.58 1.04%
Monero (XMR) $ 420.40 0.39%
Hedera (HBAR) $ 0.119865 6.41%
Toncoin (TON) $ 1.81 7.27%