Peplink Security Advisory: Balance / MAX / FusionHub Firmware 8.5.4 - Web Service components vulnerability (CVE-2026-42945)

Background
Following a recent inquiry regarding a web service vulnerability (CVE-2026-42945), we have verified and confirmed that Peplink devices running firmware versions up to 8.5.4 are affected.

Due to an outdated version of certain web service components, unauthenticated remote attackers could exploit specially crafted HTTP requests to trigger a Denial of Service (DoS) condition or achieve Remote Code Execution (RCE).

For more details, please refer to the primary advisory article (CVE-2026-42945).

Products Affected

These vulnerabilities affect the firmware (up to version 8.5.4) of the following product series:

  • Peplink Balance (including MediaFast variant)
  • MAX
  • FusionHub

Solution
This vulnerability has been resolved in firmware version 8.6.0 GA across the Peplink Balance (including MediaFast variant), MAX, and FusionHub series.

The fix is also included in the firmware 8.5.5 and 8.3.2 maintenance releases.

Published: 2026-08-21

Ref.: #36695 (8.6.0) | #37247 (8.5.5) | 37350 (8.3.2)

Credits to: James Clynes

1 Like