The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-4063, a high-severity remote code execution (RCE) vulnerability affecting Sierra Wireless AirLink ALEOS routers, to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, which allows authenticated attackers to upload malicious files via a specially crafted HTTP request to the upload.cgi endpoint, can result in arbitrary code execution with root privileges due to insufficient file upload restrictions and the elevated permissions of the ACEManager process. Cisco Talos originally disclosed the vulnerability in 2019, highlighting the risk that attackers could overwrite executable files on the device to gain full control.
CISA's action follows evidence of active exploitation in the wild and mandates that Federal Civilian Executive Branch (FCEB) agencies remediate the vulnerability to protect their networks. While the directive is binding for FCEB agencies, CISA strongly urges all organizations using affected Sierra Wireless routers to prioritize patching and mitigation efforts, as this type of vulnerability is a common vector for malicious cyber activity and poses significant risk to enterprise environments.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA directed Federal Civilian Executive Branch agencies to address CVE-2018-4063 by the specified deadline. Because many affected routers are end-of-support and may not be patchable, agencies were told to update them where possible or discontinue use by January 2, 2026.
CISA added CVE-2018-4063 to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. The agency warned the flaw poses significant risk because affected Sierra Wireless AirLink ALEOS devices are often legacy or end-of-support systems.
Research cited in later reporting said the Chaya_005 threat cluster exploited CVE-2018-4063 in early 2024, showing the router flaw was being used in real-world attacks. Honeypot observations also indicated industrial routers were being targeted by botnet and cryptominer malware.
Cisco Talos publicly disclosed CVE-2018-4063, an unrestricted file upload vulnerability in Sierra Wireless AirLink ALEOS that can enable remote code execution. The flaw affects ALEOS versions prior to 4.9.3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcewebpronews.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.