← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-10251

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:4.49%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
sierrawireless aleos all
sierrawireless es440 all
sierrawireless gx400 all
sierrawireless gx440 all
sierrawireless ls300 all
sierrawireless es450 all
sierrawireless gx450 all
sierrawireless mp70 all
sierrawireless mp70e all
sierrawireless rv50 all
sierrawireless rv50x all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.486%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2018-04-20T00:00:00
Published2018-05-04T20:00:00
Patch Date2018-04-30
Last Updated2024-08-05T07:32:01

LINK COPIED TO CLIPBOARD