Sierra Wireless develops a portfolio of industrial routers, gateways, and cellular connectivity appliances deployed across remote monitoring, critical infrastructure, and branch-office networking, making them a prominent target in the embedded-systems vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure concentrates in its AirLink product family (ES450, LX40, LX60, MP70) and its ALEOS operating system. The recurring weakness classes—including exposure of sensitive information, improper authentication, buffer overflows, and out-of-bounds writes—reflect the memory-safety and access-control challenges inherent to embedded networking firmware, particularly where legacy code and minimal input validation converge. Defenders should inventory affected appliances, restrict management-interface exposure, and prioritize patching for remotely accessible devices in mission-critical deployments. Current exploitation activity, in-the-wild adoption rates, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sierrawireless over time
Signals from CVEs in this vendor scope (60 CVEs).
60 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-4063HIGH An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a f | May 6, 2019 | 8.8 | 79 | YES | NO |
CVE-2018-4072HIGH An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task | May 6, 2019 | 8.8 | 40 | NO | NO |
CVE-2018-4073HIGH An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endp | May 6, 2019 | 8.8 | 39 | NO | NO |
CVE-2018-4061HIGH An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can | May 6, 2019 | 8.8 | 37 | NO | NO |
CVE-2018-4071HIGH An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_T | May 6, 2019 | 8.8 | 36 | NO | NO |
CVE-2018-4070HIGH An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not h | May 6, 2019 | 8.8 | 35 | NO | NO |
CVE-2018-10251CRITICAL A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be | May 4, 2018 | 9.8 | 32 | NO | NO |
CVE-2017-6044CRITICAL An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files | Jun 30, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-11851CRITICAL The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary cod | Dec 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-8782CRITICAL Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution. | Oct 6, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (60 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sierrawireless.
Media articles that mention a CVE ID that affects a product developed by Sierrawireless — matched by CVE ID, not by vendor name.