Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2026-57920 Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints. Intcontrol 2 after 2.14.2 Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2023-40146 A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command lin… Smart Reader Firmware No fix yet Fix from $2,3002024-04-17 HIGH 8.8 CVE-2023-45744 A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A speci… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 7.5 CVE-2023-43491 An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 7.5 CVE-2023-45209 An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEM… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 7.2 CVE-2023-39367EPSS 38% An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafte… Smart Reader Firmware No fix yet Fix from $1,9502024-04-17 HIGH 8.8 CVE-2023-49230 An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals'… Balance Two Firmware 8.4.0+ Fix from $1,9502023-12-28 MEDIUM 6.4 CVE-2023-49228 An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with p… Balance Two Firmware 8.4.0+ Fix from $1,6002023-12-28 HIGH 7.2 CVE-2023-49226 An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users w… Balance Two Firmware 8.4.0+ Fix from $1,9502023-12-25 HIGH 8.8 CVE-2023-34356EPSS 6% An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HT… Surf Soho Firmware No fix yet Fix from $1,9502023-10-11 HIGH 8.8 CVE-2023-35193EPSS 6% An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially … Surf Soho Firmware No fix yet Fix from $1,9502023-10-11 HIGH 8.8 CVE-2023-35194EPSS 6% An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially … Surf Soho Firmware No fix yet Fix from $1,9502023-10-11 MEDIUM 5.4 CVE-2023-34354 A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially… Surf Soho Firmware No fix yet Fix from $1,6002023-10-11 HIGH 8.8 CVE-2023-27380EPSS 6% An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted … Surf Soho Firmware No fix yet Fix from $1,9502023-10-11 HIGH 8.8 CVE-2023-28381EPSS 6% An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially cr… Surf Soho Firmware No fix yet Fix from $1,9502023-10-11 HIGH 7.5 CVE-2020-24246 Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admi… Balance 20x Firmware after 8.1.0 Fix from $1,9502020-10-07 CRITICAL 9.8 CVE-2017-8835EPSS 62% SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-… B305hw2 Firmware Patch available Fix from $2,3002017-06-05 CRITICAL 9.8 CVE-2017-8837 Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_… B305hw2 Firmware Patch available Fix from $2,3002017-06-05 HIGH 8.8 CVE-2017-8836 CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui… B305hw2 Firmware No fix yet Fix from $1,9502017-06-05 HIGH 8.1 CVE-2017-8841 Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_135… B305hw2 Firmware No fix yet Fix from $1,9502017-06-05 MEDIUM 6.1 CVE-2017-8838 XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500… B305hw2 Firmware Patch available Fix from $1,6002017-06-05 MEDIUM 6.1 CVE-2017-8839 XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_25… B305hw2 Firmware No fix yet Fix from $1,6002017-06-05 MEDIUM 5.3 CVE-2017-8840 Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw… B305hw2 Firmware Patch available Fix from $1,6002017-06-05