PT-2024-13084 · Peplink · Peplink Smart Reader

Matt Wiseman

·

Published

2023-11-30

·

Updated

2025-08-21

·

CVE-2023-43491

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions Peplink Smart Reader version 1.2.0
Description An information disclosure vulnerability exists in the web interface /cgi-bin/debug dump.cgi functionality. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this issue.
Recommendations For Peplink Smart Reader version 1.2.0, consider disabling access to the /cgi-bin/debug dump.cgi endpoint until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03302
BDU:2024-03718
CVE-2023-43491

Affected Products

Peplink Smart Reader