Known Vulnerabilities for Max Hotspot by Peplink
Listed below are 1 of the newest known vulnerabilities associated with "Max Hotspot" by "Peplink".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Peplink Max Hotspot
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48040 json | The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-22003 json | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2025-8689 json | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, HotSp... | Not Provided | 2025-09-11 | 2026-04-08 |
| CVE-2025-4764 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Informati... | Not Provided | 2026-01-22 | 2026-06-05 |
| CVE-2025-4763 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Computer In... | Not Provided | 2026-01-22 | 2026-06-05 |
| CVE-2025-4383 json | Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. T... | Not Provided | 2025-06-24 | 2026-06-05 |
| CVE-2025-1496 json | Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcin... | Not Provided | 2025-03-20 | 2026-06-06 |
| CVE-2024-4342 json | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's i... | Not Provided | 2024-06-01 | 2026-04-08 |
| CVE-2024-3500 json | The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 vi... | Not Provided | 2024-05-02 | 2026-04-08 |
| CVE-2022-21540 json | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppor... | Not Provided | 2022-07-19 | 2026-05-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Peplink | Max Hotspot | - |