HomeSecurityCVE-2018-4063 Added to CISA KEV: AirLink Router RCE

CVE-2018-4063 Added to CISA KEV: AirLink Router RCE

CISA has added CVE-2018-4063—a high-severity bug tied to Sierra Wireless AirLink routers running ALEOS/ACEManager—to its Known Exploited Vulnerabilities (KEV) catalog, a move that signals confirmed exploitation and triggers a federal remediation deadline.

The flaw, first disclosed publicly in 2019, is an unrestricted file upload issue that can be chained into remote code execution (RCE) via a specially crafted authenticated HTTP request.

What CVE-2018-4063 is and why it’s dangerous

CVE-2018-4063 affects the /cgi-bin/upload.cgi functionality in ACEManager, the web interface used to manage certain AirLink devices. The vulnerability allows an authenticated attacker to upload a file in a way that can place executable content on the device and make it reachable via the web server.

Cisco Talos’ original report focused on Sierra Wireless AirLink ES450 firmware 4.9.3, noting the issue can be abused by overwriting files that already have executable permissions—turning a “template upload” feature into code execution. Talos also noted ACEManager runs as root, which can amplify the impact if an attacker succeeds.

Severity scores: why you may see two numbers

Depending on the source, you’ll see different CVSS scores attached to CVE-2018-4063:

  • 8.8 (High) in NVD’s CVSS v3.x scoring
  • 9.9 in Cisco Talos’ scoring for the same issue

The key takeaway: regardless of which number you cite, it’s a serious authenticated-RCE risk on devices that are often deployed in distributed and industrial settings.

KEV listing adds a federal deadline

NVD’s CISA-enriched KEV metadata shows CVE-2018-4063 was added to KEV on December 12, 2025, with a required action due date of January 2, 2026 for U.S. Federal Civilian Executive Branch (FCEB) agencies. The guidance is to apply mitigations per vendor instructions (and relevant BOD guidance) or discontinue use if mitigations aren’t available.

While KEV deadlines apply to federal agencies, the listing often prompts broader action across critical infrastructure and enterprise environments, especially where similar routers are used as remote gateways.

Why this is resurfacing now: OT edge devices are under pressure

The KEV update lands amid renewed attention on attacks targeting OT network perimeter devices. In a recent 90-day honeypot analysis, Forescout Research – Vedere Labs reported that OT perimeter devices (such as routers) accounted for 67% of attacks in their environment (versus 33% for exposed OT devices like PLCs).

However, Forescout also stressed that, across all categories in the dataset, the firewall drew the most attention—after filtering out the heavy volume of SNMP noise, the firewall still “stood out as the most targeted device.”

When the focus narrowed to perimeter-device traffic, Forescout said SSH/Telnet brute-force attempts dominated (72%), while HTTP/HTTPS accounted for 24% and included exploit attempts and malware-download activity.

Forescout also mapped roughly 3,000 HTTP/HTTPS requests to attempted exploitation behavior and highlighted activity associated with malware families such as RondoDox, Redtail, and ShadowV2—presented as distribution in their observed traffic, not as a strict 1:1 linkage to specific CVEs.

Chaya_005: a cluster that began with a successful Sierra Wireless exploit

Forescout’s report described a threat cluster it dubbed Chaya_005, noting it started with a successful exploit against a Sierra Wireless router before mixing in additional malformed exploit attempts against other edge devices.

The researchers said they don’t believe Chaya_005 is currently a significant threat because they have not seen evidence of successful exploitation after the initial cluster activity.

What owners should do next

If you operate Sierra Wireless AirLink gear (particularly older deployments that still expose web management interfaces), the KEV listing is a strong signal to:

  • Inventory affected devices and firmware versions
  • Apply vendor mitigations/updates where supported
  • Restrict or remove Internet exposure for management interfaces
  • Enforce strong authentication and monitor for suspicious admin access patterns

Sierra Wireless was acquired by Semtech in 2023, and current product guidance may be published under Semtech/Sierra Wireless channels.

Sources: NVD CVE entry; Cisco Talos TALOS-2018-0748 report; Forescout Vedere Labs blog post; Semtech acquisition announcement.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -