{"id":9214,"date":"2025-12-15T10:04:42","date_gmt":"2025-12-15T10:04:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/15\/cisa-adds-sierra-router-vulnerability-to-kev-catalogue-following-active-exploitation\/"},"modified":"2025-12-15T10:04:42","modified_gmt":"2025-12-15T10:04:42","slug":"cisa-adds-sierra-router-vulnerability-to-kev-catalogue-following-active-exploitation","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/15\/cisa-adds-sierra-router-vulnerability-to-kev-catalogue-following-active-exploitation\/","title":{"rendered":"CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation"},"content":{"rendered":"<p>    CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability affecting Sierra <a href=\"https:\/\/cybersecuritynews.com\/pixie-dust-wi-fi-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Wireless routers<\/a> has been added to its Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p>This decision comes after evidence emerged that the flaw is being actively exploited in the wild. Posing significant risks to organizations that still utilize these legacy devices.<\/p>\n<p>Federal agencies and private organizations are now urged to take immediate action to secure their networks against this specific <a href=\"https:\/\/cybersecuritynews.com\/see-cyber-threats-to-your-companys-industry-region-in-2-seconds\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat<\/a>.<\/p>\n<p>The vulnerability, tracked as CVE-2018-4063, impacts the Sierra Wireless AirLink ALEOS operating system. It is described as an \u201cUnrestricted Upload of File with Dangerous Type\u201d flaw.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>CVE ID<\/strong><\/th>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2018-4063<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Description<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Vulnerability Name<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Related CWE<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-434<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Security researchers have determined that the issue allows an authenticated attacker to exploit the web server. By sending a specially crafted HTTP request, a threat actor can upload <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious files<\/a> directly to the device.<\/p>\n<p>Once a malicious file is uploaded, it can result in the execution of arbitrary code on the web server. This Remote Code Execution (<a href=\"https:\/\/cybersecuritynews.com\/7-zip-rce-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">RCE<\/a>) capability effectively gives attackers control over the compromised router.<\/p>\n<p>Although the vulnerability requires authentication to trigger, attackers often exploit it in combination with weak or default credentials to gain initial access.<\/p>\n<p>The severity of this flaw is compounded by the fact that it allows for persistent access and potential lateral movement within a network.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-end-of-life-risks-and-mitigation\"><strong>End-of-Life Risks and Mitigation<\/strong><\/h2>\n<p>A critical aspect of this alert is the status of the impacted hardware. CISA has noted that the affected Sierra Wireless AirLink products may be <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-flags-sql-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">End-of-Life<\/a> (EoL) or End-of-Service (EoS).<\/p>\n<p>This means the vendor is likely no longer releasing security updates or patches for these devices. Consequently, the standard advice to \u201cpatch immediately\u201d is not applicable here. Instead, CISA strongly <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advises<\/a> users to discontinue using these products.<\/p>\n<p>Continued use of EoL hardware leaves networks exposed to known exploits that cannot be remediated through software updates.<\/p>\n<p>Federal Civilian Executive Branch (FCEB) agencies have been given a strict deadline to remove these devices from their infrastructure to comply with Binding Operational Directive (<a href=\"https:\/\/cybersecuritynews.com\/android-0-day-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">BOD<\/a>) 22-01.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-adds-sierra-router-vulnerability\/\">CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-adds-sierra-router-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation A critical vulnerability affecting Sierra Wireless routers has been added to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes after evidence emerged that the flaw is being actively exploited in the wild. Posing significant risks to organizations that still utilize these legacy devices. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2169,131,648],"tags":[130],"class_list":["post-9214","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-exploit","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9214"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9214"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9214\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}