Vulnerability Description
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Peplink | Balance 20X Firmware | <= 8.1.0 |
| Peplink | Balance 20X | - |
| Peplink | Balance 310X Firmware | <= 8.1.0 |
| Peplink | Balance 310X | - |
| Peplink | Mbx Firmware | <= 8.1.0 |
| Peplink | Mbx | - |
| Peplink | Epx Firmware | <= 8.1.0 |
| Peplink | Epx | - |
| Peplink | Sdx Firmware | <= 8.1.0 |
| Peplink | Sdx | - |
| Peplink | Balance 30 Lte Firmware | <= 8.1.0 |
| Peplink | Balance 30 Lte | - |
| Peplink | Balance 20 Firmware | <= 8.1.0 |
| Peplink | Balance 20 | - |
| Peplink | Balance 30 Firmware | <= 8.1.0 |
| Peplink | Balance 30 | - |
| Peplink | Balance 30 Pro Firmware | <= 8.1.0 |
| Peplink | Balance 30 Pro | - |
| Peplink | Balance 50 Firmware | <= 8.1.0 |
| Peplink | Balance 50 | - |
References
- https://blog.bssi.fr/cve-2020-24246-leaking-source-file-using-the-web-admin-inteExploitThird Party Advisory
- https://download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdfRelease NotesVendor Advisory
- https://blog.bssi.fr/cve-2020-24246-leaking-source-file-using-the-web-admin-inteExploitThird Party Advisory
- https://download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdfRelease NotesVendor Advisory
FAQ
What is CVE-2020-24246?
CVE-2020-24246 is a vulnerability with a CVSS score of 7.5 (HIGH). Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
How severe is CVE-2020-24246?
CVE-2020-24246 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24246?
Check the references section above for vendor advisories and patch information. Affected products include: Peplink Balance 20X Firmware, Peplink Balance 20X, Peplink Balance 310X Firmware, Peplink Balance 310X, Peplink Mbx Firmware.