PT-2025-1309 · Tp Link · Tp-Link Tl-Sg108E

Error404Unknown

·

Published

2025-01-27

·

Updated

2025-07-16

·

CVE-2025-0730

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TP-Link TL-SG108E versions 1.0.0 Build 20201208 Rel. 40304
Description A problematic vulnerability exists in the TP-Link TL-SG108E, affecting an unknown function within the /usr account set.cgi file of the HTTP GET Request Handler component. Manipulation of the username/password arguments in a GET request with sensitive query strings can lead to information disclosure. The attack is possible remotely, though considered complex and difficult to exploit. The exploit has been publicly disclosed.
Recommendations TP-Link TL-SG108E versions prior to 1.0.0 Build 20250124 Rel. 54920 (Beta) should be upgraded to version 1.0.0 Build 20250124 Rel. 54920 (Beta) to address this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-00944
CVE-2025-0730

Affected Products

Tp-Link Tl-Sg108E