Background
Recently, a trusted security research group informed us of a vulnerability affecting Peplink devices running firmware versions 8.5.1 through 8.5.4 . After further testing, we discovered the earlier firmware version (8.3.0) is affected too.
If the Peplink device - Web Admin is enabled on LAN/WAN, the attacker can bypass the Web Admin login and is capable of gaining access to internal binaries.
Products affected
Peplink Balance (including MediaFast variant), MAX, and FusionHub product series firmware versions 8.3.0 - 8.5.4.
Solution
This issue has been resolved in Peplink Balance (including MediaFast variant), MAX, and FusionHub firmware version 8.6.0 GA.
The fix is also backported to the 8.5.5 and 8.3.2 maintenance release firmware versions.
Published: 2026-08-21
Ref.: #36935 (8.6.0) | #37209 (8.5.5) | #37227 (8.3.2)
Credits to: Christos Xenofontos and Lars Sommer