Sierra Wireless has an upgrade available to handle improper neutralization of argument delimiters in a command and exposure of sensitive information to an unauthorized actor vulnerabilities in its AirLink Router with ALEOS Software, according to a report with CISA.
Successful exploitation of these remotely exploitable vulnerabilities, discovered by Roni Gavrilov and Eran Jacob from OTORIO, could allow a loss of sensitive information and could allow remote code execution.
Sierra Wireless reports the following versions of AirLink router with ALEOS software are affected:
- Airlink Router (ES450, GX450) running ALEOS software: Versions 4.9.7 and prior
- Airlink Router (MP70, RV50, RV50x, RV55, LX 40, LX60) running ALEOS software: Versions prior to 4.16.0
In one issue, AirLink router versions with ALEOS software are vulnerable when users with valid ACEManager credentials and access to the ACEManager interface could manipulate the IP logging operation to execute arbitrary shell commands on the device.
CVE-2022-46649 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.0.
AirLink router versions with ALEOS software are vulnerable when users with valid ACEManager credentials and access to the ACEManager interface could reconfigure the device to expose the ACEManager credentials on the pre-login status page.
CVE-2022-46650 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.5.
The product sees use in multiple industrial sectors and on a global basis.
No known public exploits specifically target these vulnerabilities. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Sierra Wireless recommends upgrading the following affected devices:
Upgrade MP70, RV50, RV50x, RV55, LX 40, LX60 to ALEOS version 4.16.0 or laterÂ
Upgrade ES450, GX450 to ALEOS version 4.9.8 (when available) or laterÂ
Sierra Wireless recommends the following mitigations:
- Always use strong, and ideally unique random credentials for devices. ALEOS devices ship with unique random credentials by default.
- Disable access to ACEManager on the wide area network (WAN) and use the Sierra Wireless Airlink Management System (ALMS) or an alternative device management platform for remote management of ALEOS devices.
- If the ACEManager must remain accessible via the WAN, restrict access using measures such as Private APN, VPN, or the ALEOS Trusted IP feature (restricts access to specific hosts).

