← Back

Peplink

peplink

23 CVEs • 118 products

Products (118)

Click to collapse
Toggle
2500 Firmware
2500_firmware
Mbx Firmware
mbx_firmware
Epx Firmware
epx_firmware
Sdx Firmware
sdx_firmware
Balance 305
balance_305
Balance 380
balance_380
Balance 580
balance_580
Balance 710
balance_710
Balance 1350
balance_1350
Balance 2500
balance_2500
Balance 20x
balance_20x
Balance 310x
balance_310x
Mbx
mbx
Epx
epx
Sdx
sdx
Balance 20
balance_20
Balance 30
balance_30
Balance 50
balance_50
Balance One
balance_one
Balance Two
balance_two
Balance 210
balance_210
Balance 310
balance_310
Max Br1 Mk2
max_br1_mk2
Max Br1 Slim
max_br1_slim
Max Br1 Mini
max_br1_mini
Max Br1 M2m
max_br1_m2m
Max Br1 Ent
max_br1_ent
Max Br1 Pro
max_br1_pro
Max Br1 Ip67
max_br1__ip67
Max Br2
max_br2
Max Br1 Ip55
max_br1_ip55
Max Br2 Ip55
max_br2_ip55
Max Hd2 Ip67
max_hd2_ip67
Max Hd2 Mini
max_hd2_mini
Max Hd2
max_hd2
Max Hd1 Dome
max_hd1_dome
Max Hd2 Dome
max_hd2_dome
Max Hd4
max_hd4
Max Hd4 Ip67
max_hd4_ip67

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass an...Show more
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.Show less
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. T...Show more
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This can for example be used to change the credentials of the administrative webinterface.Show less
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/...Show more
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.Show less