CVE-2023-49228: Peplink Balance Two Firmware

Medium severity, CVSS 6.4. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root.

Affected products

  • Peplink Balance Two Firmware: before 8.4.0 (fixed in 8.4.0)

Published 2023-12-28. Last modified 2026-06-17.