Background
Following a recent inquiry regarding a web service vulnerability (CVE-2026-42945), we have verified and confirmed that Peplink devices running firmware versions up to 8.5.4 are affected.
Due to an outdated version of certain web service components, unauthenticated remote attackers could exploit specially crafted HTTP requests to trigger a Denial of Service (DoS) condition or achieve Remote Code Execution (RCE).
For more details, please refer to the primary advisory article (CVE-2026-42945).
Products Affected
These vulnerabilities affect the firmware (up to version 8.5.4) of the following product series:
- Peplink Balance (including MediaFast variant)
- MAX
- FusionHub
Solution
This vulnerability has been resolved in firmware version 8.6.0 GA across the Peplink Balance (including MediaFast variant), MAX, and FusionHub series.
The fix is also included in the firmware 8.5.5 and 8.3.2 maintenance releases.
Published: 2026-08-21
Ref.: #36695 (8.6.0) | #37247 (8.5.5) | 37350 (8.3.2)
Credits to: James Clynes