CVE-2017-8835
critical · 9.8SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.
9.8
CVSS
61.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-06-05
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| peplink | b305hw2_firmware | 7.0.1 |
| peplink | balance_305 | all versions |
| peplink | 380hw6_firmware | 7.0.1 |
| peplink | balance_380 | all versions |
| peplink | 580hw2_firmware | 7.0.1 |
| peplink | balance_580 | all versions |
| peplink | 710hw3_firmware | 7.0.1 |
| peplink | balance_710 | all versions |
| peplink | 1350hw2_firmware | 7.0.1 |
| peplink | balance_1350 | all versions |
| peplink | 2500_firmware | 7.0.1 |
| peplink | balance_2500 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-8835