CVE-2020-24246

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/10/2020
Last modified:
23/10/2020

Description

Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:peplink:balance_20x_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:balance_20x:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:balance_310x_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:balance_310x:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:mbx_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:mbx:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:epx_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:epx:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:sdx_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:sdx:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:balance_30_lte_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:balance_30_lte:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:balance_20_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)
cpe:2.3:h:peplink:balance_20:-:*:*:*:*:*:*:*
cpe:2.3:o:peplink:balance_30_firmware:*:*:*:*:*:*:*:* 8.1.0 (including)