PT-2025-1309 · Tp Link · Tp-Link Tl-Sg108E
Error404Unknown
·
Published
2025-01-27
·
Updated
2025-07-16
·
CVE-2025-0730
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-SG108E versions 1.0.0 Build 20201208 Rel. 40304
Description
A problematic vulnerability exists in the TP-Link TL-SG108E, affecting an unknown function within the
/usr account set.cgi file of the HTTP GET Request Handler component. Manipulation of the username/password arguments in a GET request with sensitive query strings can lead to information disclosure. The attack is possible remotely, though considered complex and difficult to exploit. The exploit has been publicly disclosed.Recommendations
TP-Link TL-SG108E versions prior to 1.0.0 Build 20250124 Rel. 54920 (Beta) should be upgraded to version 1.0.0 Build 20250124 Rel. 54920 (Beta) to address this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Sg108E