Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
References
| Link | Resource |
|---|---|
| https://drive.google.com/file/d/1MoZn73YkDGGpqOgaQbRU1hWVygr8VaxY/view | Exploit Third Party Advisory |
| https://drive.google.com/file/d/1MoZn73YkDGGpqOgaQbRU1hWVygr8VaxY/view | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-26 13:16
Updated : 2026-07-02 14:21
NVD link : CVE-2026-57920
Mitre link : CVE-2026-57920
CVE.ORG link : CVE-2026-57920
JSON object : View
Products Affected
peplink
- intcontrol_2
CWE
CWE-551
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
