Vulnerability record · CVE-2017-8835 · published 5 June 2017
CVE-2017-8835: Peplink Balance routers SQL injection via bauth cookie
Peplink · B305hw2 Firmware
Peplink Balance 305, 380, 580, 710, 1350 and 2500 devices running firmware before 7.0.1-build2093 contain a SQL injection in cgi-bin/MANGA/admin.cgi reachable through the bauth cookie. Because the flaw is network-reachable with no privileges or user interaction, it exposes the device management interface to unauthenticated database manipulation.
Description
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.0 base score is 9.8 with network, no-auth, no-interaction reachability, and public exploit code exists, making this a high-impact pre-auth SQL injection.
What it is
Peplink Balance 305, 380, 580, 710, 1350 and 2500 devices running firmware before 7.0.1-build2093 contain a SQL injection in cgi-bin/MANGA/admin.cgi reachable through the bauth cookie. Because the flaw is network-reachable with no privileges or user interaction, it exposes the device management interface to unauthenticated database manipulation.
Impact
An attacker can inject SQL through the bauth cookie, at minimum enumerating user accounts by observing whether a session ID is returned from the sessions database, and potentially reading or altering other data in the backend database.
Attack surface
Reached over the network by sending a crafted bauth cookie to cgi-bin/MANGA/admin.cgi on the affected Balance appliances; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.61577 (99.1st percentile) and a public Exploit-DB entry (42130) exists, indicating exploit code is publicly available and exploitation is plausible.
What to do
- Upgrade affected Balance devices to firmware 7.0.1-build2093 or later, which the vendor advisory marks as the patched release.
- Restrict management interface access to trusted networks and disable remote/WAN-side administrative access where possible.
- Rotate administrative credentials and invalidate active sessions after patching, since session data may have been exposed.
- Monitor the vendor advisory and mailing list references for any updated guidance or later fixed builds.
Detection
- Inspect web and proxy logs for requests to cgi-bin/MANGA/admin.cgi with unusual or malformed bauth cookie values.
- Alert on SQL metacharacters (quotes, UNION, comment sequences) appearing in cookie headers sent to Balance management interfaces.
- Review authentication and session logs for anomalous session ID retrieval or repeated failed account lookups.
- Baseline normal bauth cookie formats and flag deviations from expected length or character set.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/bugtraq/2017/Jun/1 | Mailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/42130/ | |
| https://www.x41-dsec.de/lab/advisories/x41-2017-005-peplink/ | PatchThird Party Advisory |
| http://seclists.org/bugtraq/2017/Jun/1 | Mailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/42130/ | |
| https://www.x41-dsec.de/lab/advisories/x41-2017-005-peplink/ | PatchThird Party Advisory |
Track CVE-2017-8835 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8835), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.