CVE-2023-34354
- EPSS 0.12%
- Veröffentlicht 11.10.2023 16:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:31
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An att...
CVE-2023-34356
- EPSS 0.3%
- Veröffentlicht 11.10.2023 16:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:31
An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigg...
CVE-2023-35193
- EPSS 0.3%
- Veröffentlicht 11.10.2023 16:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:32
An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP reques...
CVE-2023-35194
- EPSS 0.3%
- Veröffentlicht 11.10.2023 16:15:13
- Zuletzt bearbeitet 04.11.2025 20:16:32
An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP reques...
CVE-2023-27380
- EPSS 0.34%
- Veröffentlicht 11.10.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 07:52:47
An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to tri...
CVE-2023-28381
- EPSS 0.3%
- Veröffentlicht 11.10.2023 16:15:12
- Zuletzt bearbeitet 04.11.2025 20:16:25
An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request ...
CVE-2020-24246
- EPSS 0.52%
- Veröffentlicht 07.10.2020 16:15:16
- Zuletzt bearbeitet 21.11.2024 05:14:32
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.