VulnerAlert



CISCO
FIRMWARE
13-12-2025 09:42
Tags
#hacker
#exploit
#web
#server
#html
#add
#firmware
#cisco
#vulnerability
#authenticated
#security
#remote
#malicious
#flaw
#exploitable
#execution
#attack
Descripción
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw impacting AirLink ALEOS routers to its Known Vulnerabilities ( KEV ) catalog, following reports of active exploitation in the wild. CVE-2018-4063 (CVSS score: 8.8/9.9) refers an unrestricted file upload vulnerability that could be exploited achieve remote code execution by means malicious HTTP request. "A specially crafted request can file, resulting executable being uploaded, routable, webserver," agency said. "An attacker make authenticated trigger this vulnerability." Details six-year-old were publicly shared Cisco Talos April 2019, describing it as exploitable ACEManager "upload.cgi" function ES450 firmware version 4.9.3. reported Canadia... https://thehackernews.com/2025/12/cisa-adds-actively-exploited-sierra.html
Link externo
Ver detalles

Fuente
https://thehackernews.com/2025/12/cisa-adds-actively-exploited-sierra.html
Resultados similares
Coincidentes en almenos en 50% de los tags
19-12-2025 CVE-2025-14910
A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of...
Ver información
19-12-2025
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards Cert...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por