Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Conclusion & alert: CVE-2020-24246 is rated High Exploit Risk (66.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.52%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 1.00% | 0.52% | -0.49% |
| 2 | 2025-03-29 | 0.52% | 1.00% | +0.49% |
| 3 | 2025-03-17 | — | 0.52% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| peplink | balance_20x_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_20x_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_310x_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_310x_firmware:*:*:*:*:*:*:*:* |
| peplink | mbx_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mbx_firmware:*:*:*:*:*:*:*:* |
| peplink | epx_firmware | <= 8.1.0 | cpe:2.3:o:peplink:epx_firmware:*:*:*:*:*:*:*:* |
| peplink | sdx_firmware | <= 8.1.0 | cpe:2.3:o:peplink:sdx_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_30_lte_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_30_lte_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_20_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_20_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_30_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_30_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_30_pro_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_30_pro_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_50_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_50_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_one_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_one_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_two_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_two_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_210_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_210_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_310_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_310_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_305_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_305_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_380_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_380_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_580_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_580_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_710_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_710_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_1350_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_1350_firmware:*:*:*:*:*:*:*:* |
| peplink | balance_2500_firmware | <= 8.1.0 | cpe:2.3:o:peplink:balance_2500_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_mk2_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_mk2_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_classic_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_classic_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_slim_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_slim_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_mini_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_mini_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_m2m_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_m2m_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_ent_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_ent_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_pro_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_pro_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1__ip67_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1__ip67_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br2_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br2_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br1_ip55_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br1_ip55_firmware:*:*:*:*:*:*:*:* |
| peplink | max_br2_ip55_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_br2_ip55_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd2_ip67_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd2_ip67_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd2_mini_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd2_mini_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd2_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd2_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd1_dome_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd1_dome_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd2_dome_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd2_dome_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd4_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd4_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hd4_ip67_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hd4_ip67_firmware:*:*:*:*:*:*:*:* |
| peplink | max_transit_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_transit_firmware:*:*:*:*:*:*:*:* |
| peplink | max_transit_duo_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_transit_duo_firmware:*:*:*:*:*:*:*:* |
| peplink | max_transit_mini_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_transit_mini_firmware:*:*:*:*:*:*:*:* |
| peplink | max_hotspot_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_hotspot_firmware:*:*:*:*:*:*:*:* |
| peplink | max_on-the-go_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_on-the-go_firmware:*:*:*:*:*:*:*:* |
| peplink | max_700_firmware | <= 8.1.0 | cpe:2.3:o:peplink:max_700_firmware:*:*:*:*:*:*:*:* |
| peplink | ubr_lte_firmware | <= 8.1.0 | cpe:2.3:o:peplink:ubr_lte_firmware:*:*:*:*:*:*:*:* |
| peplink | surf_soho_firmware | <= 8.1.0 | cpe:2.3:o:peplink:surf_soho_firmware:*:*:*:*:*:*:*:* |
| peplink | surf_soho_mk3_firmware | <= 8.1.0 | cpe:2.3:o:peplink:surf_soho_mk3_firmware:*:*:*:*:*:*:*:* |
| peplink | mediafast_200_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mediafast_200_firmware:*:*:*:*:*:*:*:* |
| peplink | mediafast_500_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mediafast_500_firmware:*:*:*:*:*:*:*:* |
| peplink | mediafast_750_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mediafast_750_firmware:*:*:*:*:*:*:*:* |
| peplink | mediafast_hd2_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mediafast_hd2_firmware:*:*:*:*:*:*:*:* |
| peplink | mediafast_hd4_firmware | <= 8.1.0 | cpe:2.3:o:peplink:mediafast_hd4_firmware:*:*:*:*:*:*:*:* |
| peplink | speedfusion_sfe_firmware | <= 8.1.0 | cpe:2.3:o:peplink:speedfusion_sfe_firmware:*:*:*:*:*:*:*:* |
| peplink | speedfusion_sfe_cam_firmware | <= 8.1.0 | cpe:2.3:o:peplink:speedfusion_sfe_cam_firmware:*:*:*:*:*:*:*:* |
| peplink | fusionhub_firmware | <= 8.1.0 | cpe:2.3:o:peplink:fusionhub_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://blog.bssi.fr/cve-2020-24246-leaking-source-file-using-the-web-admin-interface-of-peplink-balance/ | Exploit Third Party Advisory |
| https://download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdf | Release Notes Vendor Advisory |