Vulnerabilities
Vulnerable Software
Peplink:  >> Balance Two Firmware  Security Vulnerabilities
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
CVSS Score
6.4
EPSS Score
0.001
Published
2023-12-28
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-12-28
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
CVSS Score
8.8
EPSS Score
0.355
Published
2023-12-28
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-12-25
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-10-07


Contact Us

Shodan ® - All rights reserved