CVE-2020-24246
07.10.2020, 16:15
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.Enginsight
Vendor | Product | Version |
---|---|---|
peplink | balance_20x_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_310x_firmware | 𝑥 ≤ 8.1.0 |
peplink | mbx_firmware | 𝑥 ≤ 8.1.0 |
peplink | epx_firmware | 𝑥 ≤ 8.1.0 |
peplink | sdx_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_30_lte_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_20_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_30_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_30_pro_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_50_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_50_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_one_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_two_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_210_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_210_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_310_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_305_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_380_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_580_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_710_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_1350_firmware | 𝑥 ≤ 8.1.0 |
peplink | balance_2500_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_mk2_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_classic_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_slim_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_mini_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_m2m_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_ent_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_pro_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1__ip67_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br2_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br1_ip55_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_br2_ip55_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd2_ip67_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd2_mini_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd2_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd1_dome_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd2_dome_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd4_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hd4_ip67_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_transit_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_transit_duo_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_transit_mini_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_hotspot_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_on-the-go_firmware | 𝑥 ≤ 8.1.0 |
peplink | max_700_firmware | 𝑥 ≤ 8.1.0 |
peplink | ubr_lte_firmware | 𝑥 ≤ 8.1.0 |
peplink | surf_soho_firmware | 𝑥 ≤ 8.1.0 |
peplink | surf_soho_mk3_firmware | 𝑥 ≤ 8.1.0 |
peplink | mediafast_200_firmware | 𝑥 ≤ 8.1.0 |
peplink | mediafast_500_firmware | 𝑥 ≤ 8.1.0 |
peplink | mediafast_750_firmware | 𝑥 ≤ 8.1.0 |
peplink | mediafast_hd2_firmware | 𝑥 ≤ 8.1.0 |
peplink | mediafast_hd4_firmware | 𝑥 ≤ 8.1.0 |
peplink | speedfusion_sfe_firmware | 𝑥 ≤ 8.1.0 |
peplink | speedfusion_sfe_cam_firmware | 𝑥 ≤ 8.1.0 |
peplink | fusionhub_firmware | 𝑥 ≤ 8.1.0 |
𝑥
= Vulnerable software versions
References