Vulnerabilities > CVE-2023-49230 - Missing Authorization vulnerability in Peplink Balance TWO Firmware 8.1.0

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
peplink
CWE-862

Summary

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

Vulnerable Configurations

Part Description Count
OS
Peplink
1
Hardware
Peplink
1

Common Weakness Enumeration (CWE)