VendorsSierra Wirelessrv55any version
Vulnerabilities

Sierra Wireless RV55 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-46649
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Published 2023-02-10 · Modified
8.8EPSS 0.023
CVE-2023-40465
Improper input leads to DoS
Published 2023-12-04 · Modified
8.3EPSS 0.002
CVE-2023-40463
Use of Hard-Coded Credentials
Published 2023-12-04 · Modified
8.1EPSS 0.006
CVE-2023-40461
Cross-site scripting vulnerability in ACEManager
Published 2023-12-04 · Modified
8.1EPSS 0.005
CVE-2023-40464
Use of hardcoded certificate and private key
Published 2023-12-04 · Modified
8.1EPSS 0.003
CVE-2023-40459
Improper input leads to DoS
Published 2023-12-04 · Modified
7.5EPSS 0.023
CVE-2023-38321
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
Published 2023-12-25 · Modified
7.5EPSS 0.011
CVE-2023-40462
Improper input leads to DoS
Published 2023-12-04 · Modified
7.5EPSS 0.009
CVE-2023-40460
Improper input leads to DoS
Published 2023-12-04 · Modified
7.1EPSS 0.005
CVE-2022-46650
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
Published 2023-02-10 · Modified
4.9EPSS 0.123