Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24246
Reference (s):
- https://blog.bssi.fr/cve-2020-24246-leaking-source-file-using-the-web-admin-interface-of-peplink-balance/
- https://download.peplink.com/resources/firmware-8.1.0rc1-release-notes.pdf

