CVE-2017-8841 describes an arbitrary file deletion vulnerability affecting several Peplink Balance router models running firmware versions prior to 7.0.1-build2093. This flaw, rated as High severity (CVSS 8.1), allows an authenticated attacker to delete arbitrary files on the device through an absolute path traversal in the upfile.path parameter of the firmware_process.cgi script. While no active exploitation or public exploit code (Metasploit, Nuclei) is reported, its high severity and the existence of other vulnerabilities in similar Peplink firmware versions (EDB-42130) warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:b305hw2_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:380hw6_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:580hw2_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:710hw3_firmware:7.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:o:peplink:1350hw2_firmware:7.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.