Peplink manufactures a line of enterprise and mid-market load-balancing and SD-WAN appliances, prominently the Balance series, that serve as critical routing and traffic-management chokepoints in network infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code, reflecting the appliances' internet-facing and privileged network role. The exposure recurs across Balance product models through weakness classes centered on command injection, improper access control, and cross-site scripting—flaws that directly threaten command execution, authentication bypass, and management-interface compromise on devices that control network traffic flows. Defenders should prioritize patching these appliances and restrict administrative access; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Peplink over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8835CRITICAL SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vect | Jun 5, 2017 | 9.8 | 80 | NO | YES |
CVE-2017-8837CRITICAL Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. T | Jun 5, 2017 | 9.8 | 44 | NO | YES |
CVE-2023-39367HIGH An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbi | Apr 17, 2024 | 7.2 | 39 | NO | NO |
CVE-2017-8841HIGH Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The | Jun 5, 2017 | 8.1 | 37 | NO | YES |
CVE-2017-8836HIGH CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the | Jun 5, 2017 | 8.8 | 37 | NO | YES |
CVE-2023-49230HIGH An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior a | Dec 28, 2023 | 8.8 | 36 | NO | YES |
CVE-2026-57920HIGH Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints. | Jun 26, 2026 | 7.7 | 30 | NO | NO |
CVE-2017-8840MEDIUM Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. | Jun 5, 2017 | 5.3 | 30 | NO | YES |
CVE-2017-8839MEDIUM XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affecte | Jun 5, 2017 | 6.1 | 30 | NO | YES |
CVE-2017-8838MEDIUM XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected | Jun 5, 2017 | 6.1 | 30 | NO | YES |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Peplink.
Media articles that mention a CVE ID that affects a product developed by Peplink — matched by CVE ID, not by vendor name.