Medium severity5.3NVD Advisory· Published Apr 23, 2017· Updated May 13, 2026
CVE-2017-8078
CVE-2017-8078
Description
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
Affected products
1- cpe:2.3:o:tp-link:tl-sg108e_firmware:1.1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- chmod750.com/2017/04/23/vulnerability-disclosure-tp-link/nvdExploitTechnical DescriptionThird Party Advisory
- www.securityfocus.com/bid/97985nvdThird Party AdvisoryVendor Advisory
News mentions
0No linked articles in our index yet.