Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.

Project Subscriptions

Vendors Products
Peplink Subscribe
Balance 1350 Subscribe
Balance 1350 Firmware Subscribe
Balance 20 Subscribe
Balance 20 Firmware Subscribe
Balance 20x Subscribe
Balance 20x Firmware Subscribe
Balance 210 Subscribe
Balance 210 Firmware Subscribe
Balance 2500 Subscribe
Balance 2500 Firmware Subscribe
Balance 30 Subscribe
Balance 305 Subscribe
Balance 305 Firmware Subscribe
Balance 30 Firmware Subscribe
Balance 30 Lte Subscribe
Balance 30 Lte Firmware Subscribe
Balance 30 Pro Subscribe
Balance 30 Pro Firmware Subscribe
Balance 310 Subscribe
Balance 310 Firmware Subscribe
Balance 310x Subscribe
Balance 310x Firmware Subscribe
Balance 380 Subscribe
Balance 380 Firmware Subscribe
Balance 50 Subscribe
Balance 50 Firmware Subscribe
Balance 580 Subscribe
Balance 580 Firmware Subscribe
Balance 710 Subscribe
Balance 710 Firmware Subscribe
Balance One Subscribe
Balance One Firmware Subscribe
Balance Two Subscribe
Balance Two Firmware Subscribe
Epx Firmware Subscribe
Fusionhub Subscribe
Fusionhub Firmware Subscribe
Max 700 Subscribe
Max 700 Firmware Subscribe
Max Br1 Ip67 Subscribe
Max Br1 Ip67 Firmware Subscribe
Max Br1 Classic Subscribe
Max Br1 Classic Firmware Subscribe
Max Br1 Ent Subscribe
Max Br1 Ent Firmware Subscribe
Max Br1 Ip55 Subscribe
Max Br1 Ip55 Firmware Subscribe
Max Br1 M2m Subscribe
Max Br1 M2m Firmware Subscribe
Max Br1 Mini Subscribe
Max Br1 Mini Firmware Subscribe
Max Br1 Mk2 Subscribe
Max Br1 Mk2 Firmware Subscribe
Max Br1 Pro Subscribe
Max Br1 Pro Firmware Subscribe
Max Br1 Slim Subscribe
Max Br1 Slim Firmware Subscribe
Max Br2 Subscribe
Max Br2 Firmware Subscribe
Max Br2 Ip55 Subscribe
Max Br2 Ip55 Firmware Subscribe
Max Hd1 Dome Subscribe
Max Hd1 Dome Firmware Subscribe
Max Hd2 Subscribe
Max Hd2 Dome Subscribe
Max Hd2 Dome Firmware Subscribe
Max Hd2 Firmware Subscribe
Max Hd2 Ip67 Subscribe
Max Hd2 Ip67 Firmware Subscribe
Max Hd2 Mini Subscribe
Max Hd2 Mini Firmware Subscribe
Max Hd4 Subscribe
Max Hd4 Firmware Subscribe
Max Hd4 Ip67 Subscribe
Max Hd4 Ip67 Firmware Subscribe
Max Hotspot Subscribe
Max Hotspot Firmware Subscribe
Max On-the-go Subscribe
Max On-the-go Firmware Subscribe
Max Transit Subscribe
Max Transit Duo Subscribe
Max Transit Duo Firmware Subscribe
Max Transit Firmware Subscribe
Max Transit Mini Subscribe
Max Transit Mini Firmware Subscribe
Mbx Firmware Subscribe
Mediafast 200 Subscribe
Mediafast 200 Firmware Subscribe
Mediafast 500 Subscribe
Mediafast 500 Firmware Subscribe
Mediafast 750 Subscribe
Mediafast 750 Firmware Subscribe
Mediafast Hd2 Subscribe
Mediafast Hd2 Firmware Subscribe
Mediafast Hd4 Subscribe
Mediafast Hd4 Firmware Subscribe
Sdx Firmware Subscribe
Speedfusion Sfe Subscribe
Speedfusion Sfe Cam Subscribe
Speedfusion Sfe Cam Firmware Subscribe
Speedfusion Sfe Firmware Subscribe
Surf Soho Subscribe
Surf Soho Firmware Subscribe
Surf Soho Mk3 Subscribe
Surf Soho Mk3 Firmware Subscribe
Ubr Lte Subscribe
Ubr Lte Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-16981 Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:12:08.683Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-24246

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-07T16:15:16.640

Modified: 2024-11-21T05:14:32.573

Link: CVE-2020-24246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses