Information Disclosure Vulnerability in Peplink Balance Devices
CVE-2017-8840

5.3MEDIUM

Key Information:

Vendor

Peplink

Vendor
CVE Published:
5 June 2017

What is CVE-2017-8840?

An information disclosure vulnerability exists in Peplink Balance devices where a direct request to specific URLs can leak sensitive debug information. This includes critical details such as the Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid, potentially exposing networks to unauthorized access. Devices with firmware versions prior to 7.0.1-build2093 are particularly at risk, highlighting the need for urgent updates and proactive security measures.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.