By vendor
Peplink vulnerabilities
Known CVEs affecting Peplink products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-57920HIGH 7.7
Peplink InControl 2 is vulnerable to an access-control bypass affecting REST API endpoints. An authenticated attacker can inject a semicolon character into requests to certain `/rest/o/{orgId}` endpoints to circumvent access-control rules and read sensitive organizational data. The vulnerability exists in versions through 2.14.2 and was patched on June 3, 2026. Because exploitation requires a valid login and does not enable data modification or system disruption, the risk is containable but significant for organizations managing multi-tenant deployments.