Peplink Security Advisory: Balance / MAX / FusionHub Firmware (up to 8.5.4) - SSH CLI Command Injection Vulnerability (CWE-78 / CWE-732)

Background
Recently, a trusted security research group informed us of a vulnerability affecting Peplink devices running firmware versions 8.5.1 through 8.5.4. After further testing, we discovered the earlier firmware version (8.3.0) is affected too.

If [CLI SSH & Console] access is enabled, an authenticated user logged in with an admin or user account can append malicious parameters during authentication (command injection) to gain root-level access to the router OS.

Products affected
Peplink Balance (including MediaFast variant), MAX, and FusionHub product series firmware versions 8.3.0 - 8.5.4.

Workaround
To immediately mitigate the vulnerability, manually disable the [CLI SSH & Console] setting if it is currently enabled.

Note: This setting is disabled by default.

Solution
This issue has been resolved in the Firmware 8.6.0 GA release for Peplink Balance (including MediaFast variant), MAX, and FusionHub.

The fix is also included in firmware 8.5.5 and 8.3.2 maintenance releases.

Published: 2026-08-21

Ref.: #36934 (8.6.0) | #37226 (8.5.5) | #37208 (8.3.2)

Credits to: Christos Xenofontos and Lars Sommer

1 Like