VYPR
Unrated severityNVD Advisory· Published May 6, 2019· Updated Aug 5, 2024

CVE-2018-4066

CVE-2018-4066

Description

An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A cross-site request forgery vulnerability in Sierra Wireless AirLink ES450 ACEManager allows an attacker to trick an authenticated user into performing privileged actions unintentionally.

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in the ACEManager web application of Sierra Wireless AirLink ES450 firmware version 4.9.3 [1][3]. The ACEManager lacks anti-CSRF headers, which would normally allow the server to verify that requests originate from the same session [3]. This affects the ES450 model running firmware 4.9.3; the GX450 and ES450 are all affected prior to version 4.9.4, according to CISA advisory [2].

Exploitation

An attacker can craft a malicious HTTP request and trick an authenticated user into executing it, for example by embedding the request in an email or on a website [1][3]. The victim must have an active session with the ACEManager and be logged in. No special network position is required beyond the ability to deliver the crafted link or page to the authenticated user [3]. The attacker does not need to be authenticated on the device itself.

Impact

Successful exploitation allows the attacker to perform privileged actions on the device as the authenticated user, such as modifying device configuration, changing routing settings, or managing certificates [3]. While the ACEManager is not accessible by default from the Cellular WAN, it is reachable over LAN or VPN [3]. The CVSS v3 score is 6.4, indicating a medium severity with high integrity and availability impact [3], though CISA notes a 9.1 for the overall ALEOS vulnerability set [2].

Mitigation

Sierra Wireless has addressed this vulnerability in AirLink ALEOS version 4.9.4 for GX450 and ES450 models [2]. The fix was released as part of an update that also addresses multiple other vulnerabilities [2]. Users should upgrade to firmware 4.9.4 or later. If upgrading is not immediately possible, network administrators should restrict access to the ACEManager web interface to trusted users only, and consider disabling remote access where not needed [3]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

4

News mentions

0

No linked articles in our index yet.