Exploited Known exploited (KEV) CVE-2018-4063

Sierra Wireless AirLink ALEOS unrestricted file upload (CVE-2018-4063) — the warning was issued seven years earlier

Sierra Wireless AirLink ALEOS Added to KEV Dec 12, 2025 Federal remediation due 2026-01-02

An industrial communications device accepts files containing executable code through a crafted request. An advisory for industrial control systems had been published in 2019, yet the catalog listing came in 2025, by which point the product is noted as possibly past its service life.

Key facts

  • CVE IDCVE-2018-4063
  • Affected (vendor / product)Sierra Wireless AirLink ALEOS
  • CWECWE-434
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-01-02 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • An industrial communications device accepts a file containing executable code through a crafted HTTP request (CWE-434).
  • Exploitation is described as requiring the attacker to make an authenticated HTTP request.
  • References include an advisory for industrial control systems and a manufacturer bulletin from 2019, so the warning came early.
  • The catalog listing came on 12 December 2025, seven years after numbering, with the product noted as possibly past its service life.
  • Only 1 of the 1,694 records this site holds as of 2026-09-04 names this manufacturer.

1Equipment installed and left in place

AirLink devices are installed at industrial sites to keep communications running. Once fitted, they mostly keep running. Unlike a machine someone watches all day, stopping one for an update is not a small matter. Equipment of this kind can operate for years in the state it was installed in. Seen from the vulnerability's side, that is a long stretch of not being fixed.

  1. 12018The identifier is issued
  2. 22019An advisory for industrial control systems and a manufacturer bulletin are published
  3. 3AfterwardsMaterial on the end of life of the affected model appears
  4. 4December 2025The entry is added to the catalog of exploited vulnerabilities

Laid out through its references, the warning clearly came early. The catalog listing still arrives seven years later. Since the catalog records what has been confirmed as exploited, a late listing does not mean the danger is new. Closer to the mark: an old warning is still in force.

2How to read the requirement of authentication

The description says exploitation requires an authenticated HTTP request. That looks like a demanding condition, but industrial equipment is often run with factory credentials unchanged, and shared maintenance credentials can stay in use for years. A requirement of authentication has to be read together with how well that authentication is protected. The catalog does not go that far.

3One entry in the whole catalog

Entries whose vendor is Sierra Wireless among the 1,694 this site holds as of 2026-09-041This entry alone
Entries classified as CWE-434, of those same 1,694231.4% of the total
Entries listed six to nine years after numbering, of those same 1,69418310.8% of the total

This manufacturer appears once in the entire catalog. Amid the well-known names, industrial equipment surfaces occasionally. Few entries also means few points of comparison: reading a trend against other entries from the same manufacturer is not available here. A record that stands alone has to be judged on its own.

4The route to a fix, and the route to stopping

Here too the product is noted as possibly past its service life. The measures offered are applying mitigations, or discontinuing use where none are available. On an industrial site, stopping is the hardest choice there is. Unable to update and unable to stop is the situation sitting behind an interval of seven years.

Why it matters

Equipment that is installed and left runs for years in the state it arrived in. Where stopping for an update is difficult, the time a vulnerability spends unfixed simply extends. Whether a warning was issued early and whether it was acted on are separate questions, and treating an old advisory as settled business is a habit worth dropping. Where few comparable entries exist, judgment has to rest on the single record available.

FAQ

Does requiring authentication reduce the risk?
Industrial equipment often runs with factory credentials unchanged, and maintenance credentials can stay shared for years. The condition has to be read against how well authentication is protected.
Why list it seven years later?
The catalog records what has been confirmed as exploited. A late listing does not mean the danger is new; an old warning remaining in force is the closer reading.
What if updating is not possible?
The measures given are applying mitigations or, where unavailable, discontinuing use. Confirm applicability with vendor sources and against your own environment.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Industrial equipment#End of life
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.