Peplink

Surf Soho Firmware

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 11.10.2023 16:15:13
  • Zuletzt bearbeitet 04.11.2025 20:16:31

A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An att...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.10.2023 16:15:13
  • Zuletzt bearbeitet 04.11.2025 20:16:31

An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigg...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.10.2023 16:15:13
  • Zuletzt bearbeitet 04.11.2025 20:16:32

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP reques...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.10.2023 16:15:13
  • Zuletzt bearbeitet 04.11.2025 20:16:32

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP reques...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 11.10.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:47

An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to tri...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.10.2023 16:15:12
  • Zuletzt bearbeitet 04.11.2025 20:16:25

An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 07.10.2020 16:15:16
  • Zuletzt bearbeitet 21.11.2024 05:14:32

Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.