Wednesday, September 23, 2026
Wednesday, September 23, 2026
Watch Live
UPDATED
FUEL PRICE
21-SEP-2026
PETROL
-1.70 PKR
Rs. 392.05/ltr
DIESEL
-3.12 PKR
Rs. 418.96/ltr
Headlines
Gulf stocks edge higher on oil recovery, diplomacy hopes ‘Off Campus’ S2 wraps as leaked BTS footage shakes fandom fever Rising Opioid Use Disorder crisis hits older adults Pakistan develops 'Gender Tracker' to tackle online harassment of women Bahawalpur teen plays 'Breaking Bad', arrested for poisoning father with AI help Trump’s Board of Peace recovery blueprint sets $2.45B six-month plan to rebuild Gaza Rock world in shock as Rose Tattoo frontman 'Angry Anderson' dies at 79 Massive unexploded 'WW2' bomb found near Falmouth Docks Punjab boards announce Intermediate Part-II results 2026 PM appoints Hamza Farrukh as Pakistan Climate Change Authority chair Pakistan Navy, Coast Guards foil smuggling bid in Pishukan Saudi Arabia marks 96th National Day, highlights close Pakistan-Saudi partnership Pindiz owner warns of PSL exit over Rizwan Trump meets Venezuela’s Delcy Rodriguez on UNGA sidelines Shehbaz meets Bill Gates, reaffirms push to eradicate polio ADB forecasts Pakistan growth at 3.7% for FY2027, warns of middle east risks Prime Minister Shehbaz and DPM Dar ramp up diplomacy at UN General Assembly US F-16 crashes near German air base after training exercise Pakistan foils Afghan infiltration, responds to border fire Gulf stocks edge higher on oil recovery, diplomacy hopes ‘Off Campus’ S2 wraps as leaked BTS footage shakes fandom fever Rising Opioid Use Disorder crisis hits older adults Pakistan develops 'Gender Tracker' to tackle online harassment of women Bahawalpur teen plays 'Breaking Bad', arrested for poisoning father with AI help Trump’s Board of Peace recovery blueprint sets $2.45B six-month plan to rebuild Gaza Rock world in shock as Rose Tattoo frontman 'Angry Anderson' dies at 79 Massive unexploded 'WW2' bomb found near Falmouth Docks Punjab boards announce Intermediate Part-II results 2026 PM appoints Hamza Farrukh as Pakistan Climate Change Authority chair Pakistan Navy, Coast Guards foil smuggling bid in Pishukan Saudi Arabia marks 96th National Day, highlights close Pakistan-Saudi partnership Pindiz owner warns of PSL exit over Rizwan Trump meets Venezuela’s Delcy Rodriguez on UNGA sidelines Shehbaz meets Bill Gates, reaffirms push to eradicate polio ADB forecasts Pakistan growth at 3.7% for FY2027, warns of middle east risks Prime Minister Shehbaz and DPM Dar ramp up diplomacy at UN General Assembly US F-16 crashes near German air base after training exercise Pakistan foils Afghan infiltration, responds to border fire

CISA Alerts on RCE Vulnerability in Sierra Wireless Routers

CISA urges agencies to update or discontinue use of vulnerable devices by January 2026

Web Desk December 14, 2025 Add Bol News as a trusted source

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included a critical vulnerability in Sierra Wireless AirLink ALEOS routers in its Known Exploited Vulnerabilities (KEV) catalog, following confirmation of active exploitation.

This inclusion underscores the severity of the issue, which poses a significant threat to cybersecurity across various sectors.

CVE-2018-4063 (CVSS score: 8.8/9.9) is a high-risk file upload vulnerability that allows threat actors to execute remote code by sending a specially crafted HTTP request. This vulnerability enables attackers to bypass security measures and gain unauthorized access to systems.

CISA explained that "a specifically designed HTTP request can upload a file, resulting in the execution of malicious code on the web server."

This flaw can be exploited when an attacker sends an authenticated HTTP request to trigger the vulnerability, which allows them to upload arbitrary files to the affected system.

The vulnerability was first discovered and disclosed by Cisco Talos in April 2019. They identified it as a remote code execution vulnerability within the ACEManager "upload.cgi" function of Sierra Wireless AirLink ES450 firmware version 4.9.3. Talos had reported the flaw to Sierra Wireless back in December 2018.

Sierra Wireless clarified that this vulnerability arises from a lack of restrictions in the file upload functionality within the AirLink 450 device.

When uploading template files, the file name can be arbitrarily specified, allowing an attacker to overwrite existing files on the device with malicious code. Some critical files, such as "fw_upload_init.cgi" and "fw_status.cgi," already have executable permissions, making them prime targets for exploitation.

The situation is compounded by the fact that ACEManager operates with root-level privileges, meaning any uploaded executable or shell script runs with elevated permissions, effectively allowing attackers to gain full control of the compromised device.

CVE-2018-4063 was added to CISA's KEV catalog following a 90-day honeypot analysis by Forescout, which revealed that industrial routers are among the most frequently targeted devices in operational technology (OT) environments. The analysis found that cybercriminals were actively exploiting several vulnerabilities to deliver botnet and cryptocurrency miner malware, including:

  • CVE-2024-12856 (Four-Faith routers)

  • CVE-2024-0012, CVE-2024-9474, and CVE-2025-0108 (Palo Alto Networks PAN-OS)

Additionally, Forescout reported that a newly identified threat group, Chaya_005, exploited CVE-2018-4063 in January 2024 to upload a malicious payload, "fw_upload_init.cgi." However, no further exploitation attempts have been detected since then.

Forescout Research Vedere Labs indicated that Chaya_005 is likely a broader reconnaissance campaign, testing vulnerabilities across various vendors rather than focusing on a single flaw. The group no longer appears to pose a significant threat.

Given the active exploitation of CVE-2018-4063, Federal Civilian Executive Branch (FCEB) agencies have been strongly advised to either upgrade their devices to supported versions or discontinue their use by January 2, 2026, as the product will reach its end-of-life and no longer receive security updates.

Recommended