CVE-2020-24246
Summary
| CVE | CVE-2020-24246 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-07 16:15:00 UTC |
| Updated | 2020-10-23 02:22:00 UTC |
| Description | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Peplink | Balance 1350 | hw2 | All | All | All |
| Hardware | Peplink | Balance 1350 | hw2 | All | All | All |
| Operating System | Peplink | Balance 1350 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 20 | - | All | All | All |
| Hardware | Peplink | Balance 20 | - | All | All | All |
| Hardware | Peplink | Balance 20x | - | All | All | All |
| Hardware | Peplink | Balance 20x | - | All | All | All |
| Operating System | Peplink | Balance 20x Firmware | All | All | All | All |
| Operating System | Peplink | Balance 20 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 210 | - | All | All | All |
| Hardware | Peplink | Balance 210 | - | All | All | All |
| Operating System | Peplink | Balance 210 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 2500 | - | All | All | All |
| Hardware | Peplink | Balance 2500 | - | All | All | All |
| Operating System | Peplink | Balance 2500 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 30 | - | All | All | All |
| Hardware | Peplink | Balance 30 | - | All | All | All |
| Hardware | Peplink | Balance 305 | hw2 | All | All | All |
| Hardware | Peplink | Balance 305 | hw2 | All | All | All |
| Operating System | Peplink | Balance 305 Firmware | All | All | All | All |
| Operating System | Peplink | Balance 30 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 30 Lte | - | All | All | All |
| Hardware | Peplink | Balance 30 Lte | - | All | All | All |
| Operating System | Peplink | Balance 30 Lte Firmware | All | All | All | All |
| Hardware | Peplink | Balance 30 Pro | - | All | All | All |
| Hardware | Peplink | Balance 30 Pro | - | All | All | All |
| Operating System | Peplink | Balance 30 Pro Firmware | All | All | All | All |
| Hardware | Peplink | Balance 310 | - | All | All | All |
| Hardware | Peplink | Balance 310 | - | All | All | All |
| Hardware | Peplink | Balance 310x | - | All | All | All |
| Hardware | Peplink | Balance 310x | - | All | All | All |
| Operating System | Peplink | Balance 310x Firmware | All | All | All | All |
| Operating System | Peplink | Balance 310 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 380 | hw6 | All | All | All |
| Hardware | Peplink | Balance 380 | hw6 | All | All | All |
| Operating System | Peplink | Balance 380 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 50 | - | All | All | All |
| Hardware | Peplink | Balance 50 | - | All | All | All |
| Operating System | Peplink | Balance 50 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 580 | hw2-3 | All | All | All |
| Hardware | Peplink | Balance 580 | hw2-3 | All | All | All |
| Operating System | Peplink | Balance 580 Firmware | All | All | All | All |
| Hardware | Peplink | Balance 710 | hw3 | All | All | All |
| Hardware | Peplink | Balance 710 | hw3 | All | All | All |
| Operating System | Peplink | Balance 710 Firmware | All | All | All | All |
| Hardware | Peplink | Balance One | - | All | All | All |
| Hardware | Peplink | Balance One | - | All | All | All |
| Operating System | Peplink | Balance One Firmware | All | All | All | All |
| Hardware | Peplink | Balance Two | - | All | All | All |
| Hardware | Peplink | Balance Two | - | All | All | All |
| Operating System | Peplink | Balance Two Firmware | All | All | All | All |
| Hardware | Peplink | Epx | - | All | All | All |
| Hardware | Peplink | Epx | - | All | All | All |
| Operating System | Peplink | Epx Firmware | All | All | All | All |
| Hardware | Peplink | Fusionhub | - | All | All | All |
| Hardware | Peplink | Fusionhub | - | All | All | All |
| Operating System | Peplink | Fusionhub Firmware | All | All | All | All |
| Hardware | Peplink | Max 700 | - | All | All | All |
| Hardware | Peplink | Max 700 | - | All | All | All |
| Operating System | Peplink | Max 700 Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Classic | hw2-3 | All | All | All |
| Hardware | Peplink | Max Br1 Classic | hw2-3 | All | All | All |
| Operating System | Peplink | Max Br1 Classic Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Ent | - | All | All | All |
| Hardware | Peplink | Max Br1 Ent | - | All | All | All |
| Operating System | Peplink | Max Br1 Ent Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Ip55 | hw2-4 | All | All | All |
| Hardware | Peplink | Max Br1 Ip55 | hw2-4 | All | All | All |
| Operating System | Peplink | Max Br1 Ip55 Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 M2m | - | All | All | All |
| Hardware | Peplink | Max Br1 M2m | - | All | All | All |
| Operating System | Peplink | Max Br1 M2m Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Mini | - | All | All | All |
| Hardware | Peplink | Max Br1 Mini | - | All | All | All |
| Operating System | Peplink | Max Br1 Mini Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Mk2 | - | All | All | All |
| Hardware | Peplink | Max Br1 Mk2 | - | All | All | All |
| Operating System | Peplink | Max Br1 Mk2 Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Pro | - | All | All | All |
| Hardware | Peplink | Max Br1 Pro | - | All | All | All |
| Operating System | Peplink | Max Br1 Pro Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Slim | - | All | All | All |
| Hardware | Peplink | Max Br1 Slim | - | All | All | All |
| Operating System | Peplink | Max Br1 Slim Firmware | All | All | All | All |
| Hardware | Peplink | Max Br1 Ip67 | - | All | All | All |
| Hardware | Peplink | Max Br1 Ip67 | - | All | All | All |
| Operating System | Peplink | Max Br1 Ip67 Firmware | All | All | All | All |
| Hardware | Peplink | Max Br2 | - | All | All | All |
| Hardware | Peplink | Max Br2 | - | All | All | All |
| Operating System | Peplink | Max Br2 Firmware | All | All | All | All |
| Hardware | Peplink | Max Br2 Ip55 | hw2-3 | All | All | All |
| Hardware | Peplink | Max Br2 Ip55 | hw2-3 | All | All | All |
| Operating System | Peplink | Max Br2 Ip55 Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd1 Dome | - | All | All | All |
| Hardware | Peplink | Max Hd1 Dome | - | All | All | All |
| Operating System | Peplink | Max Hd1 Dome Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd2 | - | All | All | All |
| Hardware | Peplink | Max Hd2 | - | All | All | All |
| Hardware | Peplink | Max Hd2 Dome | - | All | All | All |
| Hardware | Peplink | Max Hd2 Dome | - | All | All | All |
| Operating System | Peplink | Max Hd2 Dome Firmware | All | All | All | All |
| Operating System | Peplink | Max Hd2 Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd2 Ip67 | - | All | All | All |
| Hardware | Peplink | Max Hd2 Ip67 | - | All | All | All |
| Operating System | Peplink | Max Hd2 Ip67 Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd2 Mini | - | All | All | All |
| Hardware | Peplink | Max Hd2 Mini | - | All | All | All |
| Operating System | Peplink | Max Hd2 Mini Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd4 | - | All | All | All |
| Hardware | Peplink | Max Hd4 | - | All | All | All |
| Operating System | Peplink | Max Hd4 Firmware | All | All | All | All |
| Hardware | Peplink | Max Hd4 Ip67 | - | All | All | All |
| Hardware | Peplink | Max Hd4 Ip67 | - | All | All | All |
| Operating System | Peplink | Max Hd4 Ip67 Firmware | All | All | All | All |
| Hardware | Peplink | Max Hotspot | - | All | All | All |
| Hardware | Peplink | Max Hotspot | - | All | All | All |
| Operating System | Peplink | Max Hotspot Firmware | All | All | All | All |
| Hardware | Peplink | Max On-the-go | hw2 | All | All | All |
| Hardware | Peplink | Max On-the-go | hw2 | All | All | All |
| Operating System | Peplink | Max On-the-go Firmware | All | All | All | All |
| Hardware | Peplink | Max Transit | - | All | All | All |
| Hardware | Peplink | Max Transit | - | All | All | All |
| Hardware | Peplink | Max Transit Duo | - | All | All | All |
| Hardware | Peplink | Max Transit Duo | - | All | All | All |
| Operating System | Peplink | Max Transit Duo Firmware | All | All | All | All |
| Operating System | Peplink | Max Transit Firmware | All | All | All | All |
| Hardware | Peplink | Max Transit Mini | - | All | All | All |
| Hardware | Peplink | Max Transit Mini | - | All | All | All |
| Operating System | Peplink | Max Transit Mini Firmware | All | All | All | All |
| Hardware | Peplink | Mbx | - | All | All | All |
| Hardware | Peplink | Mbx | - | All | All | All |
| Operating System | Peplink | Mbx Firmware | All | All | All | All |
| Hardware | Peplink | Mediafast 200 | - | All | All | All |
| Hardware | Peplink | Mediafast 200 | - | All | All | All |
| Operating System | Peplink | Mediafast 200 Firmware | All | All | All | All |
| Hardware | Peplink | Mediafast 500 | - | All | All | All |
| Hardware | Peplink | Mediafast 500 | - | All | All | All |
| Operating System | Peplink | Mediafast 500 Firmware | All | All | All | All |
| Hardware | Peplink | Mediafast 750 | - | All | All | All |
| Hardware | Peplink | Mediafast 750 | - | All | All | All |
| Operating System | Peplink | Mediafast 750 Firmware | All | All | All | All |
| Hardware | Peplink | Mediafast Hd2 | - | All | All | All |
| Hardware | Peplink | Mediafast Hd2 | - | All | All | All |
| Operating System | Peplink | Mediafast Hd2 Firmware | All | All | All | All |
| Hardware | Peplink | Mediafast Hd4 | - | All | All | All |
| Hardware | Peplink | Mediafast Hd4 | - | All | All | All |
| Operating System | Peplink | Mediafast Hd4 Firmware | All | All | All | All |
| Hardware | Peplink | Sdx | - | All | All | All |
| Hardware | Peplink | Sdx | - | All | All | All |
| Operating System | Peplink | Sdx Firmware | All | All | All | All |
| Hardware | Peplink | Speedfusion Sfe | - | All | All | All |
| Hardware | Peplink | Speedfusion Sfe | - | All | All | All |
| Hardware | Peplink | Speedfusion Sfe Cam | - | All | All | All |
| Hardware | Peplink | Speedfusion Sfe Cam | - | All | All | All |
| Operating System | Peplink | Speedfusion Sfe Cam Firmware | All | All | All | All |
| Operating System | Peplink | Speedfusion Sfe Firmware | All | All | All | All |
| Hardware | Peplink | Surf Soho | hw2 | All | All | All |
| Hardware | Peplink | Surf Soho | hw2 | All | All | All |
| Operating System | Peplink | Surf Soho Firmware | All | All | All | All |
| Hardware | Peplink | Surf Soho Mk3 | - | All | All | All |
| Hardware | Peplink | Surf Soho Mk3 | - | All | All | All |
| Operating System | Peplink | Surf Soho Mk3 Firmware | All | All | All | All |
| Hardware | Peplink | Ubr Lte | - | All | All | All |
| Hardware | Peplink | Ubr Lte | - | All | All | All |
| Operating System | Peplink | Ubr Lte Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CVE-2020-24246] Leaking source file using the web admin interface of Peplink Balance - Blog BSSI | MISC | blog.bssi.fr | Exploit, Third Party Advisory |
| download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdf | MISC | download.peplink.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.