Information Disclosure Vulnerability in Peplink Balance Devices
CVE-2017-8840
5.3MEDIUM
What is CVE-2017-8840?
An information disclosure vulnerability exists in Peplink Balance devices where a direct request to specific URLs can leak sensitive debug information. This includes critical details such as the Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid, potentially exposing networks to unauthorized access. Devices with firmware versions prior to 7.0.1-build2093 are particularly at risk, highlighting the need for urgent updates and proactive security measures.
