BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA Flags High-Severity Flaw in Sierra Wireless ALEOS Routers

CISA Adds Critical Remote Code Execution Vulnerability CVE-2018-4063 in Sierra Wireless AirLink ALEOS Routers Due to Active Exploitation

  • CISA added a high-severity vulnerability in Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities catalog due to active exploitation.
  • CVE-2018-4063 allows remote code execution via an unrestricted file upload vulnerability in the router’s ACEManager “upload.cgi” function.
  • Exploitation involves sending authenticated HTTP requests to upload executable files with root privileges.
  • Forescout analysis confirmed industrial routers as heavily targeted, with active attacks by the threat group Chaya_005 using this vulnerability.
  • Federal agencies are urged to update or discontinue affected devices by January 2, 2026, as support has ended.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on December 12, 2025, added a critical vulnerability affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog. The decision follows confirmed reports of active exploitation of CVE-2018-4063, a flaw enabling remote code execution through an unrestricted file upload mechanism.

- Advertisement -

CVE-2018-4063, with a CVSS score between 8.8 and 9.9, resides in the ACEManager “upload.cgi” component of the AirLink ES450 firmware version 4.9.3. The vulnerability permits an attacker to send a specially crafted authenticated HTTP request to upload executable code to the router’s webserver. This occurs because uploaded files can overwrite existing ones without restrictions, inheriting executable permissions. Given that ACEManager runs with root privileges, uploaded scripts execute with elevated access, increasing the risk severity.

The vulnerability was first disclosed publicly by Cisco Talos in April 2019, after reporting it to Sierra Wireless in December 2018. Talos noted that critical files such as “fw_upload_init.cgi” can be replaced via this flaw, leading to full control over the device.

A recent 90-day honeypot study by Forescout identified industrial routers as prime targets in operational technology environments. Attackers often attempt to deploy Malware, including botnets and cryptocurrency miners like RondoDox, Redtail, and ShadowV2, by exploiting vulnerabilities including CVE-2018-4063. Notably, a previously unknown threat cluster named Chaya_005 weaponized this flaw in January 2024 to upload malicious payloads named “fw_upload_init.cgi.” Since then, no further successful exploitations have been observed, with Forescout deeming Chaya_005 not a “significant threat” anymore.

Due to ongoing exploitation risks and the product reaching end-of-support status, Federal Civilian Executive Branch (FCEB) agencies are advised to upgrade affected devices to a supported firmware version or discontinue their use by January 2, 2026, according to CISA’s advisory available here.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Grayscale Files for First US Worldcoin ETF

Crypto asset manager Grayscale filed an S-1 registration statement for the first US Worldcoin...

Senate CLARITY Act adds Dem customer protections

The US Senate is nearing a vote on the Digital Asset Market Clarity (CLARITY)...

FakeGit campaign uses 800 fake AI tools to spread SmartLoader malware

Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over...

Google’s New Frozen v2 Chip Aims for 2028 Launch

Google is developing a new server chip called Frozen v2, designed to optimize its...

Russia Duma approves crypto for international trade

Russia's State Duma will hold final votes on a comprehensive crypto bill on July...

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading