The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action. Per: http://www.sierrawireless.com/resources/support/airlink/docs/raven%20security%20vulnerability%202014-01-10.pdf
"Products affected by this vulnerability include the Raven X, Raven XE, Raven XT, PinPoint X, PinPoint XT and MP Products."
Publication date: Wed, 15 Jan 2014 22:08:00 +0000