VendorsPeplinkbalance_two_firmwareall versions
Vulnerabilities

Peplink Balance Two Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-49230
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
Published 2023-12-28 · Modified
8.8EPSS 0.021
CVE-2020-24246
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Published 2020-10-07 · Modified
7.5EPSS 0.013
CVE-2023-49226
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
Published 2023-12-25 · Modified
7.2EPSS 0.034
CVE-2023-49228
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
Published 2023-12-28 · Modified
6.4EPSS 0.005
CVE-2023-49229
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
Published 2023-12-28 · Modified
4.3EPSS 0.005