Loading
Generated remediation guidance and an executive summary. No account required.
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an authenticated HTTP request to trigger this vulnerability.
Use CWE-78, Sierrawireless vendor hub and Airlink Es450 Firmware product page to widen CVE-2018-4061 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-4073, CVE-2018-4072 and CVE-2018-4071 for nearby disclosures in the same product family.