Background Recently, a trusted security research group informed us of a vulnerability affecting Peplink devices running firmware versions 8.5.1 through 8.5.4 . After further testing, we discovered the earlier firmware version (8.3.0) is affected too.
If the Peplink device – Web Admin is enabled on LAN/WAN, the attacker can bypass the Web Admin login and is capable of gaining access to internal binaries.
Products affected Peplink Balance (including MediaFast variant), MAX, and FusionHub product series firmware versions 8.3.0 – 8.5.4.
Solution This issue has been resolved in Peplink Balance (including MediaFast variant), MAX, and FusionHub firmware version 8.6.0 GA.
Read the full announcement on the Peplink forum →
Where this lands in the library
Source: official Peplink announcement. Posted automatically by the Connectivity 101 news watcher; guides above are kept current by West Networks.
Leave a Reply