cbcvebase.

Peplink 1350Hw2 Firmware vulnerabilities

7 known vulnerabilities affecting peplink/1350hw2_firmware.

Total CVEs
7
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2017-8835P2CRITICALCVSS 9.8PoCv7.0.12017-06-05
CVE-2017-8835 [CRITICAL] CWE-89 CVE-2017-8835: SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware bef SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.
nvd
CVE-2017-8837P2CRITICALCVSS 9.8PoCv7.0.12017-06-05
CVE-2017-8837 [CRITICAL] CWE-522 CVE-2017-8837: Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise
nvd
CVE-2017-8836P3HIGHCVSS 8.8PoCv7.0.12017-06-05
CVE-2017-8836 [HIGH] CWE-352 CVE-2017-8836: CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b3 CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This can for example be used to change the
nvd
CVE-2017-8841P3HIGHCVSS 8.1PoCv7.0.12017-06-05
CVE-2017-8841 [HIGH] CWE-22 CVE-2017-8841: Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with fi Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter.
nvd
CVE-2017-8838P3MEDIUMCVSS 6.1PoCv7.0.12017-06-05
CVE-2017-8838 [MEDIUM] CWE-79 CVE-2017-8838: XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware be XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.
nvd
CVE-2017-8839P3MEDIUMCVSS 6.1PoCv7.0.12017-06-05
CVE-2017-8839 [MEDIUM] CWE-79 CVE-2017-8839: XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.
nvd
CVE-2017-8840P3MEDIUMCVSS 5.3PoCv7.0.12017-06-05
CVE-2017-8840 [MEDIUM] CWE-200 CVE-2017-8840: Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices wi Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid.
nvd