Peplink Security Advisory: Balance / MAX / FusionHub Firmware (up to) 8.5.4 - SSH CLI Component with multiple Vulnerabilities

Background
Courtesy of a notification from @aungkyaw_khine, multiple vulnerabilities have been identified in the OpenSSH component (< 10.3) embedded in router firmware versions up to 8.5.4 (as highlighted in this post).

A Peplink appliance is only vulnerable if the [CLI SSH & Console] option is enabled under Web Admin > System > Admin Security.

The relevant CVEs associated with the OpenSSH component are:

  • CVE-2026-35385
  • CVE-2026-35386
  • CVE-2026-35387
  • CVE-2026-35388
  • CVE-2026-35414

Products Affected
These vulnerabilities affect the firmware (up to version 8.5.4) of the following product series:

  • Peplink Balance (and Balance with MediaFast)
  • MAX
  • FusionHub

Mitigation
As a workaround for routers running firmware with an affected OpenSSH version (< 10.3), users can manually disable the [CLI SSH & Console] option if it is currently enabled.

Note: By default, this setting is disabled.

Solution
This issue has been resolved in firmware version 8.6.0 GA across the Peplink Balance, MAX, MediaFast, and FusionHub series by upgrading the OpenSSH component to version > 10.3.

The fix is also included in the firmware 8.5.5 maintenance release.

Published: 2026-08-21

Ref.: #36608 (8.6.0) | #37225 (8.5.5)

Credits to: @aungkyaw_khine

3 Likes