The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalogue, warning organizations that the vulnerability is being actively exploited in the wild.
The addition underscores the immediate security risks facing enterprises and government agencies that continue to operate these industrial routers in their network infrastructure.
Critical File Upload Vulnerability Under Active Attack
The vulnerability, tracked as CVE-2018-4063, involves an unrestricted file upload with a dangerous type weakness in Sierra Wireless AirLink ALEOS devices.
This security flaw allows attackers to upload executable code directly to the web server through a specially crafted HTTP request, bypassing standard security controls that should prevent unauthorized code execution.
Once successfully exploited, the uploaded malicious files become routable and executable on the affected system, providing attackers with potential remote code execution capabilities.
This level of access enables threat actors to establish persistent footholds within targeted networks, potentially leading to data exfiltration, lateral movement, or deployment of additional malicious payloads.
The vulnerability is associated with CWE-434, which describes weaknesses in which applications fail to validate file types during upload operations properly.
This standard programming error has been exploited across numerous platforms and applications, making it a well-understood attack vector for sophisticated threat actors.
Notably, authentication is required to exploit this flaw, meaning attackers must first obtain valid credentials before launching an attack.
However, this requirement provides only minimal protection, as credentials can often be obtained through phishing campaigns, credential stuffing, or the exploitation of other vulnerabilities.
CISA has indicated that affected Sierra Wireless AirLink ALEOS products may be approaching end of life (EoL) or end of service (EoS), significantly limiting mitigation options for organizations still using these devices.
The EoL status means manufacturers are no longer providing security updates or patches, leaving affected systems permanently vulnerable unless replaced entirely.
Users are strongly advised to discontinue using the product if patches or vendor-provided mitigations are unavailable.
For organizations that rely on these routers for critical operations, immediate device replacement should be prioritized to eliminate this attack vector.
Added to the KEV catalog on December 12, 2025, this vulnerability must be addressed by federal agencies by January 2, 2026, under Binding Operational Directive (BOD) 22-01.
This three-week remediation window reflects the severity of the threat and the confirmed active exploitation.
CISA directs organizations to apply mitigations per vendor instructions, follow the applicable guidance in BOD 22-01 for cloud services, or discontinue use of affected products entirely.
Federal Civilian Executive Branch (FCEB) agencies are required to comply with these directives, while private-sector organizations are strongly encouraged to follow the same timeline.
While it remains unknown whether CVE-2018-4063 has been used in ransomware campaigns, its inclusion in the KEV catalog confirms active exploitation attempts by malicious actors.
The vulnerability, dating back to 2018, suggests it may have been leveraged in various attack campaigns over the years.
Organizations using Sierra Wireless AirLink ALEOS routers should immediately conduct asset inventories to identify affected devices, assess their exposure to internet-facing attacks, and implement recommended security measures or plan device replacement to eliminate this risk from their environment.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates