By vendor

Peplink vulnerabilities

Known CVEs affecting Peplink products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-57920HIGH 7.7

    Peplink InControl 2 is vulnerable to an access-control bypass affecting REST API endpoints. An authenticated attacker can inject a semicolon character into requests to certain `/rest/o/{orgId}` endpoints to circumvent access-control rules and read sensitive organizational data. The vulnerability exists in versions through 2.14.2 and was patched on June 3, 2026. Because exploitation requires a valid login and does not enable data modification or system disruption, the risk is containable but significant for organizations managing multi-tenant deployments.