CVE-2020-24246: Peplink Balance 1350 Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.

Affected products

  • Peplink Balance 1350 Firmware: up to and including 8.1.0
  • Peplink Balance 20 Firmware: up to and including 8.1.0
  • Peplink Balance 20x Firmware: up to and including 8.1.0
  • Peplink Balance 210 Firmware: up to and including 8.1.0
  • Peplink Balance 2500 Firmware: up to and including 8.1.0
  • Peplink Balance 305 Firmware: up to and including 8.1.0
  • Peplink Balance 30 Firmware: up to and including 8.1.0
  • Peplink Balance 30 Lte Firmware: up to and including 8.1.0
  • Peplink Balance 30 Pro Firmware: up to and including 8.1.0
  • Peplink Balance 310 Firmware: up to and including 8.1.0
  • Peplink Balance 310x Firmware: up to and including 8.1.0
  • Peplink Balance 380 Firmware: up to and including 8.1.0
  • Peplink Balance 50 Firmware: up to and including 8.1.0
  • Peplink Balance 580 Firmware: up to and including 8.1.0
  • Peplink Balance 710 Firmware: up to and including 8.1.0
  • Peplink Balance One Firmware: up to and including 8.1.0
  • Peplink Balance Two Firmware: up to and including 8.1.0
  • Peplink Epx Firmware: up to and including 8.1.0
  • Peplink Fusionhub Firmware: up to and including 8.1.0
  • Peplink Max 700 Firmware: up to and including 8.1.0
  • Peplink Max BR1 IP67 Firmware: up to and including 8.1.0
  • Peplink Max BR1 Classic Firmware: up to and including 8.1.0
  • Peplink Max BR1 Ent Firmware: up to and including 8.1.0
  • Peplink Max BR1 IP55 Firmware: up to and including 8.1.0
  • Peplink Max BR1 m2m Firmware: up to and including 8.1.0
  • and 30 more

Published 2020-10-07. Last modified 2026-06-17.