Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Link | Tags |
---|---|
https://download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdf | release notes vendor advisory |
https://blog.bssi.fr/cve-2020-24246-leaking-source-file-using-the-web-admin-interface-of-peplink-balance/ | third party advisory exploit |