PT-2026-44972 · Tp Link · Tl-Sg108Pe V5
Christopher Walker
·
Published
2026-05-29
·
Updated
2026-05-30
·
CVE-2026-34127
CVSS v4.0
5.3
Medium
| Vector | AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:L/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-SG108PE v5 (affected versions not specified)
Description
A stored cross-site scripting (XSS) issue exists in the web management interface. This occurs because the
SYSNAM configuration parameter is not properly sanitized during the configuration file import process. An attacker with administrator access can inject a malicious script into the device configuration, which is then executed in the administrator's browser when viewing the affected interface. This could lead to session cookie theft, unauthorized configuration changes, or exposure of sensitive information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tl-Sg108Pe V5