Background
Recently, we have communicated with a security research lab that has informed us that they have found several vulnerabilities on Peplink firmware 6.3.5. Here are the details:
a. OS command injection
CVE-2023-27380, CVE-2023-28381, CVE-2023-34356, CVE-2023-35193, CVE-2023-35194
b. Cross-Site Scripting (XSS)
CVE-2023-34354
Products
Products The vulnerabilities were identified in the Balance, MAX, MediaFast, Surf SOHO, and FusionHub product families for firmware version 6.3.5.
Solution
It has been fixed in the firmware version 8.3.0/8.4.0, it can be downloaded here.