VYPR
Unrated severityNVD Advisory· Published Dec 28, 2023· Updated Aug 2, 2024

CVE-2023-49229

CVE-2023-49229

Description

Peplink Balance Two before 8.4.0 allows read-only users to obtain sensitive device configuration via missing authorization in the web service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Peplink Balance Two before 8.4.0 allows read-only users to obtain sensitive device configuration via missing authorization in the web service.

Vulnerability

An issue exists in the administration web service of Peplink Balance Two firmware versions prior to 8.4.0. A missing authorization check allows read-only, unprivileged users to access sensitive device configuration information that should be restricted. The vulnerability is present in the web interface handling of authenticated requests, where privilege level enforcement is insufficient.

Exploitation

An attacker must have valid credentials for a read-only or unprivileged account on the Peplink Balance Two device. No additional network position or user interaction beyond authentication is required. The attacker can send crafted HTTP requests to the administration web service endpoints that do not properly enforce authorization, bypassing the intended read-only restrictions.

Impact

Successful exploitation results in disclosure of sensitive device configuration data. This information can include network settings, VPN credentials, firewall rules, and other operational parameters. The attacker gains no write access or code execution, but the leaked configuration can facilitate further targeted attacks against the network. The compromise is limited to information disclosure at the read-only privilege level.

Mitigation

The issue is fixed in Peplink Balance Two firmware version 8.4.0, released December 2023. Users should upgrade to 8.4.0 or later. No workarounds are documented in the available references [1]. If upgrade is not possible, restricting access to the web interface via network segmentation may reduce risk.

References
  1. Publications

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.