Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sierrawireless

First CVE: Jan 15, 2014Active for: 13 yearsTotal CVEs: 60
53.8
VTI Score
TOP TARGET

Sierra Wireless develops a portfolio of industrial routers, gateways, and cellular connectivity appliances deployed across remote monitoring, critical infrastructure, and branch-office networking, making them a prominent target in the embedded-systems vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure concentrates in its AirLink product family (ES450, LX40, LX60, MP70) and its ALEOS operating system. The recurring weakness classes—including exposure of sensitive information, improper authentication, buffer overflows, and out-of-bounds writes—reflect the memory-safety and access-control challenges inherent to embedded networking firmware, particularly where legacy code and minimal input validation converge. Defenders should inventory affected appliances, restrict management-interface exposure, and prioritize patching for remotely accessible devices in mission-critical deployments. Current exploitation activity, in-the-wild adoption rates, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
60
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
1.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sierrawireless over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 15, 2014
12 years ago
Most Recent CVE
Dec 25, 2023
944 days ago

Products(67 total)

Top CVEs

Signals from CVEs in this vendor scope (60 CVEs).

60 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-4063HIGH
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a f
May 6, 20198.879YESNO
CVE-2018-4072HIGH
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceSet_Task
May 6, 20198.840NONO
CVE-2018-4073HIGH
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The the binary the endp
May 6, 20198.839NONO
CVE-2018-4061HIGH
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can
May 6, 20198.837NONO
CVE-2018-4071HIGH
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The EmbeddedAceTLGet_T
May 6, 20198.836NONO
CVE-2018-4070HIGH
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. This binary does not h
May 6, 20198.835NONO
CVE-2018-10251CRITICAL
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware be
May 4, 20189.832NONO
CVE-2017-6044CRITICAL
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files
Jun 30, 20179.832NONO
CVE-2019-11851CRITICAL
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary cod
Dec 26, 20229.831NONO
CVE-2020-8782CRITICAL
Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.
Oct 6, 20209.830NONO
View all 60 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products60 CVEs
23%
55%
20%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (13.3%)
Network47 (78.3%)
Unknown4 (6.7%)
Physical0 (0.0%)
Adjacent Network1 (1.7%)
Attack Complexity
Low54 (90.0%)
High2 (3.3%)
Unknown4 (6.7%)
User Interaction
None50 (83.3%)
Unknown4 (6.7%)
Required6 (10.0%)
Privileges Required
Low20 (33.3%)
High10 (16.7%)
None26 (43.3%)
Unknown4 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (60 CVEs).

CISA KEV
1 CVE
1.7% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sierrawireless.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sierrawireless — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sierrawireless's Products

View all 4 CNAs →

Top CWEs