Back to Database
Status published
High
CVE-2020-24246
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download...
Vulnerability Description
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-24246
Credits & Attribution
No credits recorded in the NVD database.
References
More from peplink
View All →CVE-2017-8841
Arbitrary file deletion exists on Peplink Balance 305, 380, 580,...
High
8.1
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580,...
Medium
5.3
CVE-2017-8839
XSS via orig_url exists on Peplink Balance 305, 380, 580,...
Medium
6.1
CVE-2017-8838
XSS via syncid exists on Peplink Balance 305, 380, 580,...
Medium
6.1
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580,...
Critical
9.8
Affected Vendor
peplink
View all reports →Affected Software
balance 20x firmware, balance 310x firmware, mbx firmware, epx firmware, sdx firmware, balance 30 lte firmware, balance 20 firmware, balance 30 firmware, balance 30 pro firmware, balance 50 firmware, balance one firmware, balance two firmware, balance 210 firmware, balance 310 firmware, balance 305 firmware, balance 380 firmware, balance 580 firmware, balance 710 firmware, balance 1350 firmware, balance 2500 firmware, max br1 mk2 firmware, max br1 classic firmware, max br1 slim firmware, max br1 mini firmware, max br1 m2m firmware, max br1 ent firmware, max br1 pro firmware, max br1 ip67 firmware, max br2 firmware, max br1 ip55 firmware, max br2 ip55 firmware, max hd2 ip67 firmware, max hd2 mini firmware, max hd2 firmware, max hd1 dome firmware, max hd2 dome firmware, max hd4 firmware, max hd4 ip67 firmware, max transit firmware, max transit duo firmware, max transit mini firmware, max hotspot firmware, max on-the-go firmware, max 700 firmware, ubr lte firmware, surf soho firmware, surf soho mk3 firmware, mediafast 200 firmware, mediafast 500 firmware, mediafast 750 firmware, mediafast hd2 firmware, mediafast hd4 firmware, speedfusion sfe firmware, speedfusion sfe cam firmware, fusionhub firmware
Vulnerable Versions:
0
Timeline
Official Publish:
October 7th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.