← Vulnerability feed

Vulnerability record · CVE-2017-8835 · published 5 June 2017

CVE-2017-8835: Peplink Balance routers SQL injection via bauth cookie

Peplink · B305hw2 Firmware

Peplink Balance 305, 380, 580, 710, 1350 and 2500 devices running firmware before 7.0.1-build2093 contain a SQL injection in cgi-bin/MANGA/admin.cgi reachable through the bauth cookie. Because the flaw is network-reachable with no privileges or user interaction, it exposes the device management interface to unauthenticated database manipulation.

9.8 CVSS 3.0 Critical EPSS 62% · top 0.9% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 3.0 base score is 9.8 with network, no-auth, no-interaction reachability, and public exploit code exists, making this a high-impact pre-auth SQL injection.

What it is

Peplink Balance 305, 380, 580, 710, 1350 and 2500 devices running firmware before 7.0.1-build2093 contain a SQL injection in cgi-bin/MANGA/admin.cgi reachable through the bauth cookie. Because the flaw is network-reachable with no privileges or user interaction, it exposes the device management interface to unauthenticated database manipulation.

Impact

An attacker can inject SQL through the bauth cookie, at minimum enumerating user accounts by observing whether a session ID is returned from the sessions database, and potentially reading or altering other data in the backend database.

Attack surface

Reached over the network by sending a crafted bauth cookie to cgi-bin/MANGA/admin.cgi on the affected Balance appliances; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.61577 (99.1st percentile) and a public Exploit-DB entry (42130) exists, indicating exploit code is publicly available and exploitation is plausible.

What to do

  • Upgrade affected Balance devices to firmware 7.0.1-build2093 or later, which the vendor advisory marks as the patched release.
  • Restrict management interface access to trusted networks and disable remote/WAN-side administrative access where possible.
  • Rotate administrative credentials and invalidate active sessions after patching, since session data may have been exposed.
  • Monitor the vendor advisory and mailing list references for any updated guidance or later fixed builds.

Detection

  • Inspect web and proxy logs for requests to cgi-bin/MANGA/admin.cgi with unusual or malformed bauth cookie values.
  • Alert on SQL metacharacters (quotes, UNION, comment sequences) appearing in cookie headers sent to Balance management interfaces.
  • Review authentication and session logs for anomalous session ID retrieval or repeated failed account lookups.
  • Baseline normal bauth cookie formats and flag deviations from expected length or character set.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8835 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-8837Peplink b305hw2 firmware insufficiently protected credentials vulnerabilityCleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_…EPSS 4.9%8.8CVE-2017-8836Peplink b305hw2 firmware cross-site request forgery vulnerabilityCSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui…EPSS 1.9%8.1CVE-2017-8841Peplink b305hw2 firmware path traversal vulnerabilityArbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_135…EPSS 3.7%6.1CVE-2017-8838Peplink b305hw2 firmware cross-site scripting vulnerabilityXSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500…EPSS 1.8%6.1CVE-2017-8839Peplink b305hw2 firmware cross-site scripting vulnerabilityXSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_25…EPSS 1.8%5.3CVE-2017-8840Peplink b305hw2 firmware information exposure vulnerabilityDebug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw…EPSS 3.6%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8835), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.