Multiple Vulnerabilities in TP-Link... CVE-2017-17745, CVE-2017-17746, CVE-2017-17747

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Overview Three vulnerabilities have been discovered in the TP-Link TL-SG108E, firmware 1.0.0 Build 20160722 Rel.50167: * CVE-2017-17745 - Cross Site Scripting (XSS) in system_name_set.cgi, sysName parameter * CVE-2017-17746 - Weak access control for user authentication * CVE-2017-17747 - Weak access control for user logout This is not an exhaustive list of vulnerabilities that may exist in the device firmware. ### Device Overview From http://www.tp-link.com.au/products/details/cat-41_TL-SG108E.html - "The TL-SG108E 8-Port Gigabit Easy Smart switch is an ideal upgrade from an unmanaged switch, designed for Small and Medium Business networks that require simple network management. Network administrators can effectively monitor traffic via Port Mirroring, Loop Prevention and Cable Diagnostics features." ### Affected Devices * Firmware Version: 1.0.0 Build 20160722 Rel.50167 * Hardware Version: TL-SG108E 3.0 * Older TL-SG108E devices may also be affected. ### Disclosure Timeline *...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息