Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-49230
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
0
Attacker Value
Unknown
CVE-2023-49229
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
0
Attacker Value
Unknown
CVE-2023-49228
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.
0
Attacker Value
Unknown
CVE-2023-49226
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
0
Attacker Value
Unknown
CVE-2020-24246
Disclosure Date: October 07, 2020 (last updated November 28, 2024)
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
0