CVE-2017-8841
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter.
Published:Jun 5, 2017
Last Modified:Apr 20, 2025
EPS:Jun 5, 2017
EPSS Score:0.04455
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Peplink
Product
1350hw2 Firmware
Peplink
1350hw2 Firmware
Vendor
Peplink
Product
2500 Firmware
Peplink
2500 Firmware
Vendor
Peplink
Product
380hw6 Firmware
Peplink
380hw6 Firmware
Vendor
Peplink
Product
580hw2 Firmware
Peplink
580hw2 Firmware
Vendor
Peplink
Product
710hw3 Firmware
Peplink
710hw3 Firmware
Vendor
Peplink
Product
B305hw2 Firmware
Peplink
B305hw2 Firmware
Vendor
Peplink
Product
Balance 1350
Peplink
Balance 1350
Vendor
Peplink
Product
Balance 2500
Peplink
Balance 2500
Vendor
Peplink
Product
Balance 305
Peplink
Balance 305
Vendor
Peplink
Product
Balance 380
Peplink
Balance 380
Vendor
Peplink
Product
Balance 580
Peplink
Balance 580
Vendor
Peplink
Product
Balance 710
Peplink
Balance 710
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
