LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 12, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 2, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-4063 to its Known Exploited Vulnerabilities catalog on Dec 12, 2025, with a federal patch deadline of Jan 2, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being…

This vulnerability affects Sierra Wireless AirLink ALEOS and allows an authenticated attacker to upload a file of dangerous type through a crafted HTTP request. The uploaded file can become executable code that is routable via the web server. The issue matters because the product may already be end-of-life or end-of-service, leaving organizations without vendor support and increasing the chance that any successful upload leads to persistent access on network-edge devices.

How it works

The weakness is classified as CWE-434, unrestricted upload of a file with dangerous type. An attacker who can already send an authenticated HTTP request supplies a specially crafted request that causes the server to accept and store a file whose type is not restricted. Once stored, the file is reachable through normal web-server paths, allowing the attacker to execute code without further authentication bypass.

Am I affected? How to find it in your systems

Sierra Wireless AirLink ALEOS typically runs on cellular routers and gateways used for remote connectivity. Inventory all such devices by querying asset-management systems, network discovery tools, or configuration databases for the ALEOS string. Confirm the exact firmware and configuration details against the vendor advisory, because the product may be marked end-of-life. Review web-server access logs for unexpected authenticated POST or PUT requests that result in new files under web-accessible directories; correlate those events with subsequent outbound connections or process-creation events on the device.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. If the advisory states that no update exists or the product has reached end-of-service, discontinue use of the affected devices. After patching or replacement, verify that the web-server upload functionality is no longer present or is restricted to approved file types and locations.

If you can't patch immediately

If your data may have been exposed

Actively exploited instances of this class of vulnerability have led to unauthorized access and data exposure in other environments. Organizations can run a free exposure scan of their corporate domains and associated email addresses against known breach data to determine whether any credentials or device identifiers already appear in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSierra Wireless · AirLink ALEOS
WeaknessCWE-434
Added to CISA KEVDec 12, 2025
Federal patch deadlineJan 2, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities