Description
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Peplink
Subscribe
1350hw2 Firmware
Subscribe
2500 Firmware
Subscribe
380hw6 Firmware
Subscribe
580hw2 Firmware
Subscribe
710hw3 Firmware
Subscribe
B305hw2 Firmware
Subscribe
Balance 1350
Subscribe
Balance 2500
Subscribe
Balance 305
Subscribe
Balance 380
Subscribe
Balance 580
Subscribe
Balance 710
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:48:22.700Z
Reserved: 2017-05-08T00:00:00.000Z
Link: CVE-2017-8835
No data.
Status : Deferred
Published: 2017-06-05T14:29:00.420
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8835
No data.
OpenCVE Enrichment
No data.
Weaknesses