CVE-2017-8837
CRITICALPeplink B305hw2 Firmware - Insufficiently Protected Credentials
Title source: ruleDescription
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1103
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
draft
Affected Products (6)
peplink/b305hw2_firmware
peplink/380hw6_firmware
peplink/580hw2_firmware
peplink/710hw3_firmware
peplink/1350hw2_firmware
peplink/2500_firmware
Timeline
Published
Jun 05, 2017
Tracked Since
Feb 18, 2026