CVE-2017-8837 describes a critical cleartext password storage vulnerability affecting various Peplink Balance router models running firmware prior to version 7.0.1-build2093. This flaw allows an attacker to access stored passwords in /etc/waipass and /etc/roapass if the device is compromised, potentially leading to further system compromise. With a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network with no user interaction, resulting in high confidentiality, integrity, and availability impacts. While not listed in KEV, the vulnerability has significant community discussion (more than 99% of all CVEs) and an ExploitDB entry (EDB-42130) detailing related issues, though no direct Metasploit or Nuclei modules are publicly available for this specific cleartext storage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:b305hw2_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:380hw6_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:580hw2_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:710hw3_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:1350hw2_firmware:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.