A stored
cross-site scripting (XSS) vulnerability has been identified in the web
management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM
configuration parameter during configuration file import. An attacker with
administrator access can inject malicious script into the device configuration,
which may be stored and executed in the administrator’s browser when the
affected interface is viewed.
Successful
exploitation may allow session cookie theft, unauthorized configuration
changes, or access to sensitive information exposed through the management
interface.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tl-sg108pe/v5/#Firmware | Product |
| https://www.tp-link.com/us/support/download/tl-sg108pe/v5/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/5110/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
01 Jun 2026, 18:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.tp-link.com/en/support/download/tl-sg108pe/v5/#Firmware - Product | |
| References | () https://www.tp-link.com/us/support/download/tl-sg108pe/v5/#Firmware - Product | |
| References | () https://www.tp-link.com/us/support/faq/5110/ - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
| CPE | cpe:2.3:h:tp-link:tl-sg108pe:5.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tl-sg108pe_firmware:1.0.1:*:*:*:*:*:*:* |
|
| First Time |
Tp-link
Tp-link tl-sg108pe Tp-link tl-sg108pe Firmware |
29 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-29 20:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-34127
Mitre link : CVE-2026-34127
CVE.ORG link : CVE-2026-34127
JSON object : View
Products Affected
tp-link
- tl-sg108pe
- tl-sg108pe_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
