S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 12, 2025

CVE-2023-49230 Scanner

CVE-2023-49230 Scanner - Unauthenticated File Upload vulnerability in Peplink Balance Two

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-49230
8.8
CVSS

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 10, 2026View on NVD →
Detail

Peplink Balance Two is a high-performance router designed for enterprise and business use, offering robust network connectivity solutions. It is utilized by organizations worldwide to manage network traffic efficiently and securely. By providing seamless failover capabilities and load balancing, it ensures uninterrupted connectivity. Its advanced features cater to various networking demands, making it a popular choice in corporate environments. Peplink constantly updates its firmware to incorporate new networking technologies and security enhancements, meeting diverse connectivity needs. The device is known for its reliability and exceptional performance in managing network resources.

The vulnerability in Peplink Balance Two allows unauthenticated attackers to upload configuration files due to missing authorization checks. This flaw affects the device's captive portal, specifically allowing file uploads via a vulnerable endpoint. Attackers can potentially modify network settings or configurations without proper authentication. This security issue poses a significant risk to network integrity and reliability. The vulnerability affects versions of Peplink Balance Two before 8.4.0. Exploiting this vulnerability could lead to unauthorized network access and potential misuse of network resources.

Technical details of the vulnerability reveal that the upload endpoint /guest/portal_admin_upload.cgi lacks proper authorization checks. Attackers can manipulate this endpoint by sending specially crafted requests. The configuration changes due to unauthenticated file uploads are reflected at /guest/preview.cgi?portal_id=1. The missing authorization checks make it possible for attackers to exploit this endpoint to upload feasible configurations. Additionally, the successful exploitation is evident from specific response patterns indicating save success in the server feedback. Such technical missteps allow unauthorized alterations to the device's configuration.

If exploited, this vulnerability can lead to significant disruptions within the network. Malicious users could alter network settings or redirect traffic, potentially causing data breaches or service interruptions. Such unauthorized access could corrupt configuration files, leading to network instability or downtime. The sensitivity of the router's configuration framework makes exploitation risks severe, possibly leading to exposure of sensitive network information. It further risks hampering the operational capabilities the router offers to its users, leading to potential financial and reputational damage. Impacts could vary based on how the network is structured and what configurations an attacker modifies.

REFERENCES

Solution Advice
  • Update Peplink Balance Two firmware to version 8.4.0 or later to patch the vulnerability.
  • Implement strict access control measures to restrict unauthorized access to configuration endpoints.
  • Regularly review and monitor device logs for any unauthorized configuration change attempts.
  • Enhance security policies to cover potential file upload mechanisms within the network infrastructure.
  • Educate network administrators on the importance of maintaining up-to-date device firmware and security settings.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-49230 Scanner - Unauthenticated File Upload vulnerability in Peplink Balance Two | S4E