Background Recently, a trusted security research group informed us of a vulnerability affecting Peplink devices running firmware versions 8.5.1 through 8.5.4. After further testing, we discovered the earlier firmware version (8.3.0) is affected too.
If [CLI SSH & Console] access is enabled, an authenticated user logged in with an admin or user account can append malicious parameters during authentication (command injection) to gain root-level access to the router OS.
Products affected Peplink Balance (including MediaFast variant), MAX, and FusionHub product series firmware versions 8.3.0 – 8.5.4.
Workaround To immediately mitigate the vulnerability, manually disable the [CLI SSH & Console] setting if it is currently enabled.
Read the full announcement on the Peplink forum →
Where this lands in the library
Source: official Peplink announcement. Posted automatically by the Connectivity 101 news watcher; guides above are kept current by West Networks.
Leave a Reply