Known Vulnerabilities for Max Br1 Classic by Peplink
Listed below are 1 of the newest known vulnerabilities associated with "Max Br1 Classic" by "Peplink".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Peplink Max Br1 Classic
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33368 | Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic W... | Not Provided | 2026-03-20 | 2026-03-23 |
| CVE-2026-28528 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET_FOLD... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-28527 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_AP... | Not Provided | 2026-03-30 | 2026-04-01 |
| CVE-2026-28526 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLAYER_A... | Not Provided | 2026-03-30 | 2026-03-30 |
| CVE-2026-28367 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminat... | Not Provided | 2026-03-27 | 2026-04-01 |
| CVE-2026-2389 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ... | Not Provided | 2026-03-26 | 2026-03-26 |
| CVE-2025-58029 | Missing Authorization vulnerability in Sumit Singh Classic Widgets with Block-based Widgets classic-widgets-with-block-based-... | Not Provided | 2025-09-22 | 2026-04-01 |
| CVE-2025-31641 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider... | Not Provided | 2025-05-16 | 2026-04-01 |
| CVE-2024-56286 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic Addons... | Not Provided | 2025-01-07 | 2026-04-01 |
| CVE-2024-47312 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Grim Classic Editor ... | Not Provided | 2024-10-17 | 2026-04-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Peplink | Max Br1 Classic | hw2-3 | All | All | All |